Security Advisories
All Advisories
TYPO3-EXT-SA-2025-004: Insecure Direct Object Reference in extension "Download manager" (reint_downloadmanager)
It has been discovered that the extension "Download manager" (reint_downloadmanager) is susceptible to Insecure Direct Object Reference.
TYPO3-CORE-SA-2025-016: Privilege Escalation to System Maintainer
It has been discovered that TYPO3 CMS is susceptible to broken authentication.
TYPO3-CORE-SA-2025-015: Broken Authentication in Backend MFA
It has been discovered that TYPO3 CMS is susceptible to broken authentication.
TYPO3-CORE-SA-2025-014: Unrestricted File Upload in File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2025-013: Unverified Password Change for Backend Users
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2025-012: Server-Side Request Forgery via Webhooks
It has been discovered that TYPO3 CMS is susceptible to server side request forgery..
TYPO3-CORE-SA-2025-011: Information Disclosure via DBAL Restriction Handling
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-EXT-SA-2025-003: Multiple vulnerabilities in extension “[clickstorm] SEO” (cs_seo)
It has been discovered that the extension "[clickstorm] SEO" (cs_seo) is susceptible to Cross-Site Scripting and Insecure Direct Object Reference.
TYPO3-EXT-SA-2025-002: Cross-Site Scripting in extension “Additional TCA” (additional_tca)
It has been discovered that the extension “Additional TCA” (additional_tca) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
It has been discovered that the extension "OpenID Connect Authentication" (oidc) is susceptible to Account Takeover.
TYPO3-CORE-SA-2025-010: Cross-Site Request Forgery in DB Check Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-009: Cross-Site Request Forgery in Scheduler Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-008: Cross-Site Request Forgery in Indexed Search Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-007: Cross-Site Request Forgery in Form Framework Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-006: Cross-Site Request Forgery in Extension Manager Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-005: Cross-Site Request Forgery in Dashboard Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-004: Cross-Site Request Forgery in Backend User Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-003: Cross-Site Request Forgery in Log Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-002: Potential Open Redirect via Parsing Differences
It has been discovered that TYPO3 CMS is susceptible to open redirect.
TYPO3-CORE-SA-2025-001: Information Disclosure via Exception Handling/Logger
It has been discovered that TYPO3 CMS is susceptible to information disclosure.