Technology · Packagist
typo3/cms (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 32 vulnerabilities in typo3/cms (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, TYPO3 Broken Access Control in Localization Handling, was published on 7 June 2024.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest typo3/cms (Packagist) vulnerabilities
- TYPO3 Broken Access Control in Localization HandlinglowCVSS 3.1
- Typo3 Cross-Site Scripting in Language Pack Handlinginfo
- Typo3 Broken Access Control in Import Moduleinfo
- Typo3 Information Disclosure in Page Treeinfo
- Typo3 Information Disclosure in User Authenticationinfo
- Cross-Site Scripting in TYPO3 CMS BackendlowCVSS 3.1
- Authentication Bypass in TYPO3 FrontendlowCVSS 3.1
- Typo3 Arbitrary File Disclosure in Form Componentinfo
- Cross-Site Scripting (XSS) in TYPO3 component Backendinfo
- TYPO3 Cross-Site Scripting (XSS) in form componentinfo
- TYPO3 Cross-Site Scripting in legacy form componentinfo
- TYPO3 SQL Injection in dbalinfo
- Cross-Site Scripting in TYPO3 component Indexed Searchinfo
- TYPO3 is susceptible to Cross-Site Flashinginfo
- CVE-2022-36104: TYPO3 CMS vulnerable to Denial of Service in Page Error HandlinglowCVSS 3.1EPSS 1.6%
- CVE-2014-3944: TYPO3 Improper Session InvalidationinfoEPSS 1.3%
- CVE-2014-3945: TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hashmediumCVSS 4EPSS 1.6%
- CVE-2014-3946: Typo3 Information DisclosureinfoEPSS 1.1%
- CVE-2015-8756: TYPO3 CMS indexed search Cross-site Scripting vulnerabilitylowCVSS 3EPSS 0.8%
- CVE-2015-8760: TYPO3 allows remote attackers to embed Flash videos from external domainlowCVSS 3EPSS 1.4%
- CVE-2013-4701: PHP OpenID Library Denial of Service vulnerabilityinfoEPSS 3.0%
- CVE-2018-6905: Typo3 XSS VulnerabilitylowCVSS 3EPSS 2.2%
- CVE-2017-6370: TYPO3 Information Disclosure VulnerabilitylowCVSS 3EPSS 1.0%
- CVE-2010-1153: TYPO3 PHP remote file inclusion vulnerabilitymediumCVSS 4EPSS 1.2%
- CVE-2005-4875: TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`infoEPSS 1.4%
Most severe typo3/cms (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2016-4056: TYPO3 CMS stored XSS in Backend bookmark toolbarmediumCVSS 6.1EPSS 1.1%
- CVE-2014-3945: TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hashmediumCVSS 4EPSS 1.6%
- CVE-2010-1153: TYPO3 PHP remote file inclusion vulnerabilitymediumCVSS 4EPSS 1.2%
- CVE-2022-36104: TYPO3 CMS vulnerable to Denial of Service in Page Error HandlinglowCVSS 3.1EPSS 1.6%
- CVE-2011-3583: Typo3 SQL injection due to faulty prepared statementslowCVSS 3.1EPSS 1.4%
- CVE-2021-41114: HTTP Host Header InjectionlowCVSS 3.1EPSS 1.2%
- CVE-2020-11063: Information Disclosure in Password ResetlowCVSS 3.1EPSS 1.2%
- CVE-2011-4900: Typo3 Information DisclosurelowCVSS 3.1EPSS 0.9%
- CVE-2021-41113: Cross-Site-Request-Forgery in BackendlowCVSS 3.1EPSS 0.6%
- CVE-2020-26229: XML External Entity in Dashboard WidgetlowCVSS 3.1EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/packagist-typo3-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "typo3/cms (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/packagist-typo3-cms, 28 September 2026.