Junglewise Threat Intelligence

CVE-2026-47348: TYPO3 CMS XSS in Indexed Search component

CVE-2026-47348 · Severity: medium · CVSS 4 · Published 2026-06-09

Technologies: Typo3 Cms-Core. Vendors: Typo3.

Executive brief

TYPO3 CMS is a popular open-source content management system used for building and managing websites. A security flaw in its search functionality allows authorized editors to inject malicious scripts into page titles. If a visitor views these titles in search results, the script could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the TYPO3 Indexed Search (indexed_search) extension. The root cause is a failure to sanitize page titles before they are stored in the search index and a subsequent failure to apply proper output encoding when these titles are rendered in frontend search results. An attacker with 'editor' privileges (Privileges Required: Low) can include HTML markup in page titles. When a victim performs a search that returns the malicious page title, the payload executes in the victim's browser context. This issue is fixed in TYPO3 versions 13.4.31 and 14.3.3.

Affected products

  • TYPO3 TYPO3 CMS 13.0.0 to 13.4.30, 14.0.0 to 14.3.2
  • TYPO3 Indexed Search (indexed_search) 13.0.0 to 13.4.30, 14.0.0 to 14.3.2

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: patched
  • 2026-06-12: advisory

References