{"schema_version":1,"title":"TYPO3 CMS Core vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in TYPO3 CMS Core: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, TYPO3 CMS broken access control in backend and install tool, was published on 11 August 2026.","url":"https://junglewise.ai/threats/technologies/cms-core","json_url":"https://junglewise.ai/threats/technologies/cms-core.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cms-core","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":15,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":12},"latest":[{"cvss":7.3,"slug":"typo3-cms-broken-access-control-in-backend-and-install-tool-aa5ab01f","title":"TYPO3 CMS broken access control in backend and install tool","severity":"high","exploited":false,"published_at":"2026-08-11T09:32:33+00:00","url":"https://junglewise.ai/threats/typo3-cms-broken-access-control-in-backend-and-install-tool-aa5ab01f"},{"cve":"CVE-2026-49742","cvss":4,"epss":0.0046,"slug":"cve-2026-49742-typo3-cms-broken-access-control-in-media-module","title":"TYPO3 CMS broken access control in Media Module","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:53.65+00:00","url":"https://junglewise.ai/threats/cve-2026-49742-typo3-cms-broken-access-control-in-media-module"},{"cve":"CVE-2026-49741","cvss":4,"epss":0.0037,"slug":"cve-2026-49741-typo3-cms-broken-access-control-in-form-framework-form-definition","title":"TYPO3 CMS broken access control in Form Framework form_definition table","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:53.52+00:00","url":"https://junglewise.ai/threats/cve-2026-49741-typo3-cms-broken-access-control-in-form-framework-form-definition"},{"cve":"CVE-2026-49740","cvss":4,"epss":0.0059,"slug":"cve-2026-49740-typo3-cms-insecure-deserialization-in-variablefrontend-and","title":"TYPO3 CMS insecure deserialization in VariableFrontend and Registry","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:53.38+00:00","url":"https://junglewise.ai/threats/cve-2026-49740-typo3-cms-insecure-deserialization-in-variablefrontend-and"},{"cve":"CVE-2026-49738","cvss":4,"epss":0.0052,"slug":"cve-2026-49738-typo3-cms-path-traversal-in-generalutility-isallowedabspath","title":"TYPO3 CMS path traversal in GeneralUtility::isAllowedAbsPath","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:53.247+00:00","url":"https://junglewise.ai/threats/cve-2026-49738-typo3-cms-path-traversal-in-generalutility-isallowedabspath"},{"cve":"CVE-2026-47352","cvss":4,"epss":0.0041,"slug":"cve-2026-47352-typo3-cms-broken-access-control-in-backend-api","title":"TYPO3 CMS broken access control in Backend API","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:53.12+00:00","url":"https://junglewise.ai/threats/cve-2026-47352-typo3-cms-broken-access-control-in-backend-api"},{"cve":"CVE-2026-47350","cvss":4,"epss":0.0041,"slug":"cve-2026-47350-typo3-cms-broken-access-control-in-datahandler","title":"TYPO3 CMS broken access control in DataHandler","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:52.86+00:00","url":"https://junglewise.ai/threats/cve-2026-47350-typo3-cms-broken-access-control-in-datahandler"},{"cve":"CVE-2026-47349","cvss":4,"epss":0.0041,"slug":"cve-2026-47349-typo3-cms-missing-authorization-in-recycler-module","title":"TYPO3 CMS missing authorization in Recycler module","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:52.72+00:00","url":"https://junglewise.ai/threats/cve-2026-47349-typo3-cms-missing-authorization-in-recycler-module"},{"cve":"CVE-2026-47347","cvss":4,"epss":0.0048,"slug":"cve-2026-47347-typo3-cms-open-redirect-in-generalutility-sanitizelocalurl","title":"TYPO3 CMS open redirect in GeneralUtility::sanitizeLocalUrl","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:52.457+00:00","url":"https://junglewise.ai/threats/cve-2026-47347-typo3-cms-open-redirect-in-generalutility-sanitizelocalurl"},{"cve":"CVE-2026-47346","cvss":4,"epss":0.0044,"slug":"cve-2026-47346-typo3-cms-privilege-escalation-in-form-framework-via-mixed-case","title":"TYPO3 CMS privilege escalation in Form Framework via mixed-case extensions","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:52.32+00:00","url":"https://junglewise.ai/threats/cve-2026-47346-typo3-cms-privilege-escalation-in-form-framework-via-mixed-case"},{"cve":"CVE-2026-47343","cvss":4,"epss":0.0041,"slug":"cve-2026-47343-typo3-cms-broken-access-control-in-file-abstraction-layer","title":"TYPO3 CMS broken access control in File Abstraction Layer","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:52.193+00:00","url":"https://junglewise.ai/threats/cve-2026-47343-typo3-cms-broken-access-control-in-file-abstraction-layer"},{"cve":"CVE-2026-11607","cvss":4,"epss":0.0024,"slug":"cve-2026-11607-typo3-cms-privilege-escalation-in-form-framework","title":"TYPO3 CMS privilege escalation in Form Framework","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:47.027+00:00","url":"https://junglewise.ai/threats/cve-2026-11607-typo3-cms-privilege-escalation-in-form-framework"},{"cve":"CVE-2018-17960","cvss":3,"epss":0.0195,"slug":"cve-2018-17960-ckeditor-4-xss-in-source-mode-paste","title":"CKEditor 4 XSS in source mode paste","severity":"low","exploited":false,"published_at":"2018-11-21T22:19:50+00:00","url":"https://junglewise.ai/threats/cve-2018-17960-ckeditor-4-xss-in-source-mode-paste"},{"cve":"CVE-2018-14041","cvss":3,"epss":0.0431,"slug":"cve-2018-14041-bootstrap-cross-site-scripting-in-scrollspy-data-target","title":"Bootstrap cross-site scripting in scrollspy data-target","severity":"low","exploited":false,"published_at":"2018-09-13T15:49:56+00:00","url":"https://junglewise.ai/threats/cve-2018-14041-bootstrap-cross-site-scripting-in-scrollspy-data-target"},{"cve":"CVE-2016-4056","cvss":6.1,"epss":0.0108,"slug":"cve-2016-4056-typo3-cms-stored-xss-in-backend-bookmark-toolbar","title":"TYPO3 CMS stored XSS in Backend bookmark toolbar","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:01.377+00:00","url":"https://junglewise.ai/threats/cve-2016-4056-typo3-cms-stored-xss-in-backend-bookmark-toolbar"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"TYPO3 CMS Core","slug":"cms-core","vendor":{"name":"Typo3","slug":"typo3","url":"https://junglewise.ai/threats/vendors/typo3"},"aliases":[],"category":"cms","homepage":"https://typo3.org/","repo_url":"https://github.com/TYPO3/typo3","description":"The central framework and core components of the TYPO3 content management system.","url":"https://junglewise.ai/threats/technologies/cms-core"},"most_severe":[{"cvss":7.3,"slug":"typo3-cms-broken-access-control-in-backend-and-install-tool-aa5ab01f","title":"TYPO3 CMS broken access control in backend and install tool","severity":"high","exploited":false,"published_at":"2026-08-11T09:32:33+00:00","url":"https://junglewise.ai/threats/typo3-cms-broken-access-control-in-backend-and-install-tool-aa5ab01f"},{"cve":"CVE-2026-49742","cvss":4,"epss":0.0046,"slug":"cve-2026-49742-typo3-cms-broken-access-control-in-media-module","title":"TYPO3 CMS broken access control in Media Module","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:53.65+00:00","url":"https://junglewise.ai/threats/cve-2026-49742-typo3-cms-broken-access-control-in-media-module"},{"cve":"CVE-2026-47346","cvss":4,"epss":0.0044,"slug":"cve-2026-47346-typo3-cms-privilege-escalation-in-form-framework-via-mixed-case","title":"TYPO3 CMS privilege escalation in Form Framework via mixed-case extensions","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:52.32+00:00","url":"https://junglewise.ai/threats/cve-2026-47346-typo3-cms-privilege-escalation-in-form-framework-via-mixed-case"},{"cve":"CVE-2026-47343","cvss":4,"epss":0.0041,"slug":"cve-2026-47343-typo3-cms-broken-access-control-in-file-abstraction-layer","title":"TYPO3 CMS broken access control in File Abstraction Layer","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:52.193+00:00","url":"https://junglewise.ai/threats/cve-2026-47343-typo3-cms-broken-access-control-in-file-abstraction-layer"},{"cve":"CVE-2026-49741","cvss":4,"epss":0.0037,"slug":"cve-2026-49741-typo3-cms-broken-access-control-in-form-framework-form-definition","title":"TYPO3 CMS broken access control in Form Framework form_definition table","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:53.52+00:00","url":"https://junglewise.ai/threats/cve-2026-49741-typo3-cms-broken-access-control-in-form-framework-form-definition"},{"cve":"CVE-2026-11607","cvss":4,"epss":0.0024,"slug":"cve-2026-11607-typo3-cms-privilege-escalation-in-form-framework","title":"TYPO3 CMS privilege escalation in Form Framework","severity":"high","exploited":false,"published_at":"2026-06-09T11:16:47.027+00:00","url":"https://junglewise.ai/threats/cve-2026-11607-typo3-cms-privilege-escalation-in-form-framework"},{"cve":"CVE-2016-4056","cvss":6.1,"epss":0.0108,"slug":"cve-2016-4056-typo3-cms-stored-xss-in-backend-bookmark-toolbar","title":"TYPO3 CMS stored XSS in Backend bookmark toolbar","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:01.377+00:00","url":"https://junglewise.ai/threats/cve-2016-4056-typo3-cms-stored-xss-in-backend-bookmark-toolbar"},{"cve":"CVE-2026-49740","cvss":4,"epss":0.0059,"slug":"cve-2026-49740-typo3-cms-insecure-deserialization-in-variablefrontend-and","title":"TYPO3 CMS insecure deserialization in VariableFrontend and Registry","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:53.38+00:00","url":"https://junglewise.ai/threats/cve-2026-49740-typo3-cms-insecure-deserialization-in-variablefrontend-and"},{"cve":"CVE-2026-49738","cvss":4,"epss":0.0052,"slug":"cve-2026-49738-typo3-cms-path-traversal-in-generalutility-isallowedabspath","title":"TYPO3 CMS path traversal in GeneralUtility::isAllowedAbsPath","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:53.247+00:00","url":"https://junglewise.ai/threats/cve-2026-49738-typo3-cms-path-traversal-in-generalutility-isallowedabspath"},{"cve":"CVE-2026-47347","cvss":4,"epss":0.0048,"slug":"cve-2026-47347-typo3-cms-open-redirect-in-generalutility-sanitizelocalurl","title":"TYPO3 CMS open redirect in GeneralUtility::sanitizeLocalUrl","severity":"medium","exploited":false,"published_at":"2026-06-09T11:16:52.457+00:00","url":"https://junglewise.ai/threats/cve-2026-47347-typo3-cms-open-redirect-in-generalutility-sanitizelocalurl"}],"generated_at":"2026-09-26T19:07:00.176898+00:00"}