This is a mature, actively maintained TYPO3 core release with a long release history, frequent recent releases, a non-archived organization-backed repository, substantial recent commit activity, and a broad contributor base. Licensing is explicit and supported by a license file, lifecycle scripts are absent, and the repository clearly references the package despite the monorepo name mismatch. The main reservations are the absence of a repository security policy and security-scanning tooling, plus the package's large runtime dependency surface; missing packaged tests and changelog are less concerning because the repository contains tests and the package is a large core component. Overall, it appears safe to depend on from a maintenance and supply-chain transparency perspective, subject to normal review of its many transitive dependencies.
88%
Total Score
100
50
89
90
The release declares 63 runtime dependencies, including substantial Symfony, Doctrine, and HTTP-related components; this is understandable for a framework core but increases transitive maintenance and upgrade exposure.
The artifact includes a README but no packaged tests or changelog; the missing packaged tests are compensated by repository tests, while the absent changelog is a minor transparency gap for a mature package.
Composer build tooling is present, but no security-scanning tools were detected; the missing scanning capability is a supply-chain hygiene gap, though not evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and coordinated-disclosure practices less transparent for a security-sensitive core framework.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-11607 typo3/cms-core is vulnerable to Missing Authorization in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3. | 0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more | High |
CVE-2026-47349 typo3/cms-core is vulnerable to Missing Authorization in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3. | 0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more | Medium |
CVE-2026-47347 typo3/cms-core is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3. | 0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more | Medium |
CVE-2026-47343 typo3/cms-core is vulnerable to Missing Authorization in versions 0.0.0 - 10.4.57, 11.0.0 - 11.5.51, 12.0.0 - 12.4.46, 13.0.0 - 13.4.31 and 14.0.0 - 14.3.3. | 0.0.0 - 10.4.5711.0.0 - 11.5.5112.0.0 - 12.4.46 +2 more | High |
CVE-2026-49741 typo3/cms-core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 14.0.0 - 14.3.3. | 14.0.0 - 14.3.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.1 | — | — |
psr/clock Version ^1.0 | — | — |
symfony/uid Version ^7.4.8 | — | — |
symfony/mime Version ^7.4.12 | — | — |
symfony/yaml Version ^7.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.