{"schema_version":1,"title":"typo3/cms (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in typo3/cms (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, TYPO3 Broken Access Control in Localization Handling, was published on 7 June 2024.","url":"https://junglewise.ai/threats/technologies/packagist-typo3-cms","json_url":"https://junglewise.ai/threats/technologies/packagist-typo3-cms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/packagist-typo3-cms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":32,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cvss":3.1,"slug":"typo3-broken-access-control-in-localization-handling-c5bdd897","title":"TYPO3 Broken Access Control in Localization Handling","severity":"low","exploited":false,"published_at":"2024-06-07T17:15:33+00:00","url":"https://junglewise.ai/threats/typo3-broken-access-control-in-localization-handling-c5bdd897"},{"slug":"typo3-cross-site-scripting-in-language-pack-handling-0b94d64f","title":"Typo3 Cross-Site Scripting in Language Pack Handling","severity":"info","exploited":false,"published_at":"2024-06-05T17:23:19+00:00","url":"https://junglewise.ai/threats/typo3-cross-site-scripting-in-language-pack-handling-0b94d64f"},{"slug":"typo3-broken-access-control-in-import-module-45d1c0cd","title":"Typo3 Broken Access Control in Import Module","severity":"info","exploited":false,"published_at":"2024-06-05T17:22:52+00:00","url":"https://junglewise.ai/threats/typo3-broken-access-control-in-import-module-45d1c0cd"},{"slug":"typo3-information-disclosure-in-page-tree-130f7db5","title":"Typo3 Information Disclosure in Page Tree","severity":"info","exploited":false,"published_at":"2024-06-05T17:21:19+00:00","url":"https://junglewise.ai/threats/typo3-information-disclosure-in-page-tree-130f7db5"},{"slug":"typo3-information-disclosure-in-user-authentication-e7bd018d","title":"Typo3 Information Disclosure in User Authentication","severity":"info","exploited":false,"published_at":"2024-06-05T17:09:30+00:00","url":"https://junglewise.ai/threats/typo3-information-disclosure-in-user-authentication-e7bd018d"},{"cvss":3.1,"slug":"cross-site-scripting-in-typo3-cms-backend-22823c56","title":"Cross-Site Scripting in TYPO3 CMS Backend","severity":"low","exploited":false,"published_at":"2024-06-05T17:07:15+00:00","url":"https://junglewise.ai/threats/cross-site-scripting-in-typo3-cms-backend-22823c56"},{"cvss":3.1,"slug":"authentication-bypass-in-typo3-frontend-567944d6","title":"Authentication Bypass in TYPO3 Frontend","severity":"low","exploited":false,"published_at":"2024-06-05T16:55:00+00:00","url":"https://junglewise.ai/threats/authentication-bypass-in-typo3-frontend-567944d6"},{"slug":"typo3-arbitrary-file-disclosure-in-form-component-0e377d42","title":"Typo3 Arbitrary File Disclosure in Form Component","severity":"info","exploited":false,"published_at":"2024-06-04T15:01:36+00:00","url":"https://junglewise.ai/threats/typo3-arbitrary-file-disclosure-in-form-component-0e377d42"},{"slug":"cross-site-scripting-xss-in-typo3-component-backend-fb206c92","title":"Cross-Site Scripting (XSS) in TYPO3 component Backend","severity":"info","exploited":false,"published_at":"2024-06-04T14:45:20+00:00","url":"https://junglewise.ai/threats/cross-site-scripting-xss-in-typo3-component-backend-fb206c92"},{"slug":"typo3-cross-site-scripting-xss-in-form-component-5b4a668d","title":"TYPO3 Cross-Site Scripting (XSS) in form component","severity":"info","exploited":false,"published_at":"2024-06-03T19:42:12+00:00","url":"https://junglewise.ai/threats/typo3-cross-site-scripting-xss-in-form-component-5b4a668d"},{"slug":"typo3-cross-site-scripting-in-legacy-form-component-d832de11","title":"TYPO3 Cross-Site Scripting in legacy form component","severity":"info","exploited":false,"published_at":"2024-06-03T19:41:40+00:00","url":"https://junglewise.ai/threats/typo3-cross-site-scripting-in-legacy-form-component-d832de11"},{"slug":"typo3-sql-injection-in-dbal-046f8318","title":"TYPO3 SQL Injection in dbal","severity":"info","exploited":false,"published_at":"2024-06-03T16:46:05+00:00","url":"https://junglewise.ai/threats/typo3-sql-injection-in-dbal-046f8318"},{"slug":"cross-site-scripting-in-typo3-component-indexed-search-89fdbfda","title":"Cross-Site Scripting in TYPO3 component Indexed Search","severity":"info","exploited":false,"published_at":"2024-06-03T14:41:04+00:00","url":"https://junglewise.ai/threats/cross-site-scripting-in-typo3-component-indexed-search-89fdbfda"},{"slug":"typo3-is-susceptible-to-cross-site-flashing-0217b366","title":"TYPO3 is susceptible to Cross-Site Flashing","severity":"info","exploited":false,"published_at":"2024-06-03T14:39:16+00:00","url":"https://junglewise.ai/threats/typo3-is-susceptible-to-cross-site-flashing-0217b366"},{"cve":"CVE-2022-36104","cvss":3.1,"epss":0.0161,"slug":"cve-2022-36104-typo3-cms-vulnerable-to-denial-of-service-in-page-error-handling","title":"TYPO3 CMS vulnerable to Denial of Service in Page Error Handling","severity":"low","exploited":false,"published_at":"2022-09-16T17:16:46+00:00","url":"https://junglewise.ai/threats/cve-2022-36104-typo3-cms-vulnerable-to-denial-of-service-in-page-error-handling"},{"cve":"CVE-2014-3944","epss":0.0131,"slug":"cve-2014-3944-typo3-improper-session-invalidation","title":"TYPO3 Improper Session Invalidation","severity":"info","exploited":false,"published_at":"2022-05-17T04:42:47+00:00","url":"https://junglewise.ai/threats/cve-2014-3944-typo3-improper-session-invalidation"},{"cve":"CVE-2014-3945","cvss":4,"epss":0.0164,"slug":"cve-2014-3945-typo3-vulnerable-to-authentication-bypass-via-leveraging-knowledge","title":"TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash","severity":"medium","exploited":false,"published_at":"2022-05-17T04:42:47+00:00","url":"https://junglewise.ai/threats/cve-2014-3945-typo3-vulnerable-to-authentication-bypass-via-leveraging-knowledge"},{"cve":"CVE-2014-3946","epss":0.0112,"slug":"cve-2014-3946-typo3-information-disclosure","title":"Typo3 Information Disclosure","severity":"info","exploited":false,"published_at":"2022-05-17T04:42:47+00:00","url":"https://junglewise.ai/threats/cve-2014-3946-typo3-information-disclosure"},{"cve":"CVE-2015-8756","cvss":3,"epss":0.008,"slug":"cve-2015-8756-typo3-cms-indexed-search-cross-site-scripting-vulnerability","title":"TYPO3 CMS indexed search Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-17T03:59:52+00:00","url":"https://junglewise.ai/threats/cve-2015-8756-typo3-cms-indexed-search-cross-site-scripting-vulnerability"},{"cve":"CVE-2015-8760","cvss":3,"epss":0.0143,"slug":"cve-2015-8760-typo3-allows-remote-attackers-to-embed-flash-videos-from-external","title":"TYPO3 allows remote attackers to embed Flash videos from external domain","severity":"low","exploited":false,"published_at":"2022-05-17T03:59:51+00:00","url":"https://junglewise.ai/threats/cve-2015-8760-typo3-allows-remote-attackers-to-embed-flash-videos-from-external"},{"cve":"CVE-2013-4701","epss":0.03,"slug":"cve-2013-4701-php-openid-library-denial-of-service-vulnerability","title":"PHP OpenID Library Denial of Service vulnerability","severity":"info","exploited":false,"published_at":"2022-05-17T03:46:28+00:00","url":"https://junglewise.ai/threats/cve-2013-4701-php-openid-library-denial-of-service-vulnerability"},{"cve":"CVE-2018-6905","cvss":3,"epss":0.0217,"slug":"cve-2018-6905-typo3-xss-vulnerability","title":"Typo3 XSS Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T03:25:24+00:00","url":"https://junglewise.ai/threats/cve-2018-6905-typo3-xss-vulnerability"},{"cve":"CVE-2017-6370","cvss":3,"epss":0.0099,"slug":"cve-2017-6370-typo3-information-disclosure-vulnerability","title":"TYPO3 Information Disclosure Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:46:32+00:00","url":"https://junglewise.ai/threats/cve-2017-6370-typo3-information-disclosure-vulnerability"},{"cve":"CVE-2010-1153","cvss":4,"epss":0.0116,"slug":"cve-2010-1153-typo3-php-remote-file-inclusion-vulnerability","title":"TYPO3 PHP remote file inclusion vulnerability","severity":"medium","exploited":false,"published_at":"2022-05-02T06:19:32+00:00","url":"https://junglewise.ai/threats/cve-2010-1153-typo3-php-remote-file-inclusion-vulnerability"},{"cve":"CVE-2005-4875","epss":0.0138,"slug":"cve-2005-4875-typo3-reveals-sensitive-information-via-direct-request-to-misc","title":"TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`","severity":"info","exploited":false,"published_at":"2022-05-01T02:31:34+00:00","url":"https://junglewise.ai/threats/cve-2005-4875-typo3-reveals-sensitive-information-via-direct-request-to-misc"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"typo3/cms (Packagist)","slug":"packagist-typo3-cms","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/packagist-typo3-cms"},"most_severe":[{"cve":"CVE-2016-4056","cvss":6.1,"epss":0.0108,"slug":"cve-2016-4056-typo3-cms-stored-xss-in-backend-bookmark-toolbar","title":"TYPO3 CMS stored XSS in Backend bookmark toolbar","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:01.377+00:00","url":"https://junglewise.ai/threats/cve-2016-4056-typo3-cms-stored-xss-in-backend-bookmark-toolbar"},{"cve":"CVE-2014-3945","cvss":4,"epss":0.0164,"slug":"cve-2014-3945-typo3-vulnerable-to-authentication-bypass-via-leveraging-knowledge","title":"TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash","severity":"medium","exploited":false,"published_at":"2022-05-17T04:42:47+00:00","url":"https://junglewise.ai/threats/cve-2014-3945-typo3-vulnerable-to-authentication-bypass-via-leveraging-knowledge"},{"cve":"CVE-2010-1153","cvss":4,"epss":0.0116,"slug":"cve-2010-1153-typo3-php-remote-file-inclusion-vulnerability","title":"TYPO3 PHP remote file inclusion vulnerability","severity":"medium","exploited":false,"published_at":"2022-05-02T06:19:32+00:00","url":"https://junglewise.ai/threats/cve-2010-1153-typo3-php-remote-file-inclusion-vulnerability"},{"cve":"CVE-2022-36104","cvss":3.1,"epss":0.0161,"slug":"cve-2022-36104-typo3-cms-vulnerable-to-denial-of-service-in-page-error-handling","title":"TYPO3 CMS vulnerable to Denial of Service in Page Error Handling","severity":"low","exploited":false,"published_at":"2022-09-16T17:16:46+00:00","url":"https://junglewise.ai/threats/cve-2022-36104-typo3-cms-vulnerable-to-denial-of-service-in-page-error-handling"},{"cve":"CVE-2011-3583","cvss":3.1,"epss":0.0137,"slug":"cve-2011-3583-typo3-sql-injection-due-to-faulty-prepared-statements","title":"Typo3 SQL injection due to faulty prepared statements","severity":"low","exploited":false,"published_at":"2022-04-22T00:24:17+00:00","url":"https://junglewise.ai/threats/cve-2011-3583-typo3-sql-injection-due-to-faulty-prepared-statements"},{"cve":"CVE-2021-41114","cvss":3.1,"epss":0.0122,"slug":"cve-2021-41114-http-host-header-injection","title":"HTTP Host Header Injection","severity":"low","exploited":false,"published_at":"2021-10-05T20:23:35+00:00","url":"https://junglewise.ai/threats/cve-2021-41114-http-host-header-injection"},{"cve":"CVE-2020-11063","cvss":3.1,"epss":0.0119,"slug":"cve-2020-11063-information-disclosure-in-password-reset","title":"Information Disclosure in Password Reset","severity":"low","exploited":false,"published_at":"2020-05-13T22:19:21+00:00","url":"https://junglewise.ai/threats/cve-2020-11063-information-disclosure-in-password-reset"},{"cve":"CVE-2011-4900","cvss":3.1,"epss":0.0095,"slug":"cve-2011-4900-typo3-information-disclosure","title":"Typo3 Information Disclosure","severity":"low","exploited":false,"published_at":"2022-04-22T00:24:10+00:00","url":"https://junglewise.ai/threats/cve-2011-4900-typo3-information-disclosure"},{"cve":"CVE-2021-41113","cvss":3.1,"epss":0.0064,"slug":"cve-2021-41113-cross-site-request-forgery-in-backend","title":"Cross-Site-Request-Forgery in Backend","severity":"low","exploited":false,"published_at":"2021-10-05T20:23:47+00:00","url":"https://junglewise.ai/threats/cve-2021-41113-cross-site-request-forgery-in-backend"},{"cve":"CVE-2020-26229","cvss":3.1,"epss":0.0064,"slug":"cve-2020-26229-xml-external-entity-in-dashboard-widget","title":"XML External Entity in Dashboard Widget","severity":"low","exploited":false,"published_at":"2020-11-23T21:18:44+00:00","url":"https://junglewise.ai/threats/cve-2020-26229-xml-external-entity-in-dashboard-widget"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}