typo3/cms-backend v14.3.7 appears to be a healthy, mature dependency. It has a long release history beginning in 2017, 270 releases including 40 in the last 12 months, a stable non-prerelease version, no registry deprecation, active recent repository work, and 19 contributors with limited concentration of commits. The package is backed by the TYPO3-CMS organization, is licensed under GPL-2.0-or-later, and has substantial source and artifact contents. The main reservations are the absence of a repository security policy and security-scanning tooling, plus no changelog in the collected package or repository metadata; these are transparency and assurance gaps, but they are outweighed by the strong release and maintenance evidence.
88%
Total Score
100
100
94
90
Composer build tooling is present, supporting reproducible project conventions, but no security-scanning tools were detected, leaving a modest assurance gap.
The repository has no SECURITY.md or other detected security policy, which weakens vulnerability-reporting transparency for a security-sensitive backend component.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-885460 typo3/cms-backend is vulnerable to Missing Authorization in versions 10.0.0 - 13.4.34 and 14.0.0 - 14.3.6. | 10.0.0 - 13.4.3414.0.0 - 14.3.6 | Medium |
CVE-2026-19418 typo3/cms-backend is vulnerable to Origin Validation Error in versions 13.0.0 - 13.4.34. | 13.0.0 - 13.4.34 | High |
CVE-2026-6553 typo3/cms-backend is vulnerable to Cleartext Storage of Sensitive Information in versions 14.2.0 - 14.2.0. | 14.2.0 - 14.2.0 | High |
CVE-2025-59020 typo3/cms-backend is vulnerable to Incorrect Authorization in versions 14.0.0 - 14.0.1, 13.0.0 - 13.4.22, 12.0.0 - 12.4.40, 11.0.0 - 11.5.48 and 10.0.0 - 10.4.54. | 10.0.0 - 10.4.5411.0.0 - 11.5.4812.0.0 - 12.4.40 +2 more | Medium |
CVE-2025-59019 typo3/cms-backend is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 12.0.0 - 12.4.37 and 13.0.0 - 13.4.18. | 12.0.0 - 12.4.3713.0.0 - 13.4.18 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.