TYPO3 CMS Core
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-0859 typo3/cms-core is vulnerable to Deserialization of Untrusted Data in versions 14.0.0 - 14.0.1, 13.0.0 - 13.4.22, 12.0.0 - 12.4.40, 11.0.0 - 11.5.48 and 10.0.0 - 10.4.54. | 10.0.0 - 10.4.5411.0.0 - 11.5.4812.0.0 - 12.4.40 +2 more | Medium |
CVE-2025-59016 typo3/cms-core is vulnerable to Generation of Error Message Containing Sensitive Information in versions 9.0.0 - 9.5.55, 10.0.0 - 10.4.54, 11.0.0 - 11.5.48, 12.0.0 - 12.4.37 and 13.0.0 - 13.4.18. | 9.0.0 - 9.5.5510.0.0 - 10.4.5411.0.0 - 11.5.48 +2 more | Medium |
CVE-2025-59015 typo3/cms-core is vulnerable to Insufficient Entropy in versions 12.0.0 - 12.4.37 and 13.0.0 - 13.4.18. | 12.0.0 - 12.4.3713.0.0 - 13.4.18 | Medium |
CVE-2025-59013 typo3/cms-core is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 9.0.0 - 9.5.55, 10.0.0 - 10.4.54, 11.0.0 - 11.5.48, 12.0.0 - 12.4.37 and 13.0.0 - 13.4.18. | 9.0.0 - 9.5.5510.0.0 - 10.4.5411.0.0 - 11.5.48 +2 more | Medium |
CVE-2025-47940 typo3/cms-core is vulnerable to Unverified Ownership in versions 10.4.0 - 10.4.49, 11.0.0 - 11.5.43, 12.0.0 - 12.4.30 and 13.0.0 - 13.4.11. | 10.4.0 - 10.4.4911.0.0 - 11.5.4312.0.0 - 12.4.30 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.1 | — | — |
symfony/uid Version ^7.3 | — | — |
symfony/mime Version ^7.3 | — | — |
symfony/yaml Version ^7.3 | — | — |
doctrine/dbal Version ~4.3.3 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant