Vendor
Typo3 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 34 vulnerabilities in Typo3: 0 in the last 7 days and 13 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2023-50462, was published on 14 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 0
- Exploited in the wild
- 0
About Typo3
PHP content management system and framework for building web applications.
Typo3 technologies
Latest Typo3 vulnerabilities
- CVE-2023-50462: TYPO3 Content Consent extension insecure direct object referencemediumCVSS 5.3EPSS 0.3%
- CVE-2023-50461: TYPO3 Direct Mail configuration injection in backend modulehighCVSS 8.8EPSS 0.3%
- CVE-2026-77139: TYPO3 Mask extension path traversal in template handlinginfoCVSS 6.5EPSS 0.4%
- CVE-2026-77138: TYPO3 HTML5 Video Player vs. Powermail extension remote code executioninfoCVSS 9.8EPSS 0.7%
- CVE-2026-77137: TYPO3 Forms Export SQL injection in backend moduleinfoCVSS 7.3EPSS 0.4%
- CVE-2026-77130: TYPO3 SYSSY insufficient JWT token expiration validationinfoCVSS 5.7EPSS 0.4%
- CVE-2026-77129: TYPO3 sf_event_mgt Server-Side Template Injection in email subjectinfoCVSS 7.1EPSS 0.4%
- CVE-2026-77128: TYPO3 sf_event_mgt broken access control on event visibilityinfoCVSS 7.5EPSS 0.5%
- CVE-2026-77127: TYPO3 Modules extension information disclosure in backend AJAX endpointinfoCVSS 6.5EPSS 0.4%
- CVE-2026-56096: TYPO3 Apache Solr for TYPO3 information disclosure in search queryinfoCVSS 7.5EPSS 0.4%
- TYPO3 CMS broken access control in backend and install toolhighCVSS 7.3
- CVE-2026-19418: The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0, where TYPO3 CMS startedhighCVSS 7.3EPSS 0.2%
- CVE-2026-15305: TYPO3 CMS unrestricted file upload in Form FrameworkmediumCVSS 6.3EPSS 0.3%
- CVE-2026-49742: TYPO3 CMS broken access control in Media ModulehighCVSS 7.1EPSS 0.0%
- CVE-2026-49741: TYPO3 CMS broken access control in Form Framework form_definition tablehighCVSS 8.7EPSS 0.0%
- CVE-2026-49740: TYPO3 CMS insecure deserialization in VariableFrontend and RegistrymediumCVSS 6.3EPSS 0.3%
- CVE-2026-49738: TYPO3 CMS path traversal in GeneralUtility::isAllowedAbsPathlowCVSS 2.1EPSS 0.0%
- CVE-2026-47352: TYPO3 CMS broken access control in Backend APImediumCVSS 5.3EPSS 0.0%
- CVE-2026-47350: TYPO3 CMS broken access control in DataHandlermediumCVSS 5.3EPSS 0.0%
- CVE-2026-47349: TYPO3 CMS missing authorization in Recycler modulemediumCVSS 5.3EPSS 0.0%
- CVE-2026-47348: TYPO3 CMS XSS in Indexed Search componentmediumCVSS 5.1EPSS 0.0%
- CVE-2026-47347: TYPO3 CMS open redirect in GeneralUtility::sanitizeLocalUrlmediumCVSS 5.3EPSS 0.0%
- CVE-2026-47346: TYPO3 CMS privilege escalation in Form Framework via mixed-case extensionshighCVSS 7.6EPSS 0.0%
- CVE-2026-47343: TYPO3 CMS broken access control in File Abstraction LayerhighCVSS 7.2EPSS 0.0%
- CVE-2026-11607: TYPO3 CMS privilege escalation in Form FrameworkhighCVSS 7.6EPSS 0.0%
Most severe Typo3 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-50461: TYPO3 Direct Mail configuration injection in backend modulehighCVSS 8.8EPSS 0.3%
- CVE-2026-49741: TYPO3 CMS broken access control in Form Framework form_definition tablehighCVSS 8.7EPSS 0.0%
- CVE-2026-8827: TYPO3 tt_address SQL injection in AddressRepositoryhighCVSS 8.2EPSS 0.3%
- CVE-2026-8726: TYPO3 News system SQL injection in Date Menu pluginhighCVSS 8.2EPSS 0.1%
- CVE-2026-11607: TYPO3 CMS privilege escalation in Form FrameworkhighCVSS 7.6EPSS 0.0%
- CVE-2026-47346: TYPO3 CMS privilege escalation in Form Framework via mixed-case extensionshighCVSS 7.6EPSS 0.0%
- CVE-2026-19418: The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0, where TYPO3 CMS startedhighCVSS 7.3EPSS 0.2%
- TYPO3 CMS broken access control in backend and install toolhighCVSS 7.3
- CVE-2026-47343: TYPO3 CMS broken access control in File Abstraction LayerhighCVSS 7.2EPSS 0.0%
- CVE-2026-8727: TYPO3 Site Crawler insecure deserialization in X-T3Crawler-Meta headerhighCVSS 7.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 8 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/typo3.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Typo3 vulnerabilities", https://junglewise.ai/threats/vendors/typo3, 26 September 2026.