This is a healthy, mature release with strong maintenance and project backing. It has been published since 2017 with 270 releases, 40 releases in the last 12 months, a stable non-prerelease version, active recent development with 41 commits from 13 maintainers, and an organization-owned, non-archived repository. The package is licensed, has substantial source content, and its missing artifact tests and changelog are compensated by repository tests and the package's established release history. The main reservations are the absence of a repository security policy and security-scanning tooling, plus limited repository popularity, but these do not outweigh the evidence of active and distributed maintenance.
88%
Total Score
100
100
94
90
Composer build tooling is present, but no security-scanning tools were detected; this is a modest supply-chain hygiene gap rather than evidence of abandonment.
The repository has no security policy, which reduces transparency about vulnerability reporting and handling for a framework component.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-15305 typo3/cms-form is vulnerable to Insufficient Type Distinction in versions 14.2.0 - 14.3.4. | 14.2.0 - 14.3.4 | Medium |
CVE-2024-55922 typo3/cms-form is vulnerable to Cross-Site Request Forgery (CSRF) in versions 10.0.0 - 10.4.47, 11.0.0 - 11.5.41, 12.0.0 - 12.4.24 and 13.0.0 - 13.4.2. | 10.0.0 - 10.4.4711.0.0 - 11.5.4112.0.0 - 12.4.24 +1 more | Medium |
CVE-2021-21358 typo3/cms-form is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 10.2.0 - 10.4.13 and 11.0.0 - 11.1.0. | 10.2.0 - 10.4.1311.0.0 - 11.1.0 | Medium |
CVE-2021-21355 typo3/cms-form is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 8.0.0 - 8.7.39, 9.0.0 - 9.5.24, 10.0.0 - 10.4.13 and 11.0.0 - 11.1.0. | 8.0.0 - 8.7.399.0.0 - 9.5.2410.0.0 - 10.4.13 +1 more | High |
CVE-2021-21357 typo3/cms-form is vulnerable to Improper Input Validation in versions 8.0.0 - 8.7.39, 9.0.0 - 9.5.24, 10.0.0 - 10.4.13 and 11.0.0 - 11.1.0. | 8.0.0 - 8.7.399.0.0 - 9.5.2410.0.0 - 10.4.13 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
typo3/cms-frontend Version 14.3.7 | — | — |
symfony/expression-language Version ^7.4.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.