typo3/cms-backend
Packagist25 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cms-backendpage 1 of 1
- CVE-2008-5644MEDIUMCVSS v2 4.3EG 4.3fixed in 4.2.32008-12-17
vulnerable: 4.2.2
Cross-site scripting (XSS) vulnerability in the file backend module in TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- CVE-2009-3628MEDIUMCVSS v2 4.0EG 4.0fixed in 4.1.13, 4.2.10 or 4.3beta2, by version range2009-11-02
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content form element.
- CVE-2009-3629LOWCVSS v2 3.5EG 3.5fixed in 4.1.13, 4.2.10 or 4.3beta2, by version range2009-11-02
Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allow remote authenticated users to inject arbitrary web scrip…
- CVE-2009-3630MEDIUMCVSS v2 5.5EG 5.5fixed in 4.1.13, 4.2.10 or 4.3beta2, by version range2009-11-02
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters, rel…
- CVE-2009-3631HIGHCVSS v2 8.5EG 8.5fixed in 4.1.13, 4.2.10 or 4.3beta2, by version range2009-11-02
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via…
- CVE-2010-3659MEDIUMCVSS 5.4EG 5.4fixed in 4.1.14, 4.2.13, 4.3.4 or 4.4.1, by version range2017-10-20
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspe…
- CVE-2010-3660MEDIUMCVSS 5.4EG 5.4fixed in 4.1.14, 4.2.13, 4.3.4 or 4.4.1, by version range2019-11-01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
- CVE-2010-3661MEDIUMCVSS 6.1EG 6.1fixed in 4.1.14, 4.2.13, 4.3.4 or 4.4.1, by version range2019-11-01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
- CVE-2010-3662HIGHCVSS 8.8EG 8.8fixed in 4.1.14, 4.2.13, 4.3.4 or 4.4.1, by version range2019-11-04
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
- CVE-2010-3663HIGHCVSS 8.8EG 8.8fixed in 4.1.14, 4.2.13, 4.3.4 or 4.4.1, by version range2019-11-04
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.
- CVE-2010-3664MEDIUMCVSS 6.5EG 6.5fixed in 4.1.14, 4.2.13, 4.3.4 or 4.4.1, by version range2019-11-04
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
- CVE-2010-3715MEDIUMCVSS v2 4.3EG 4.3fixed in 4.2.15, 4.3.7 or 4.4.4, by version range2010-10-25
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, a…
- CVE-2021-21340MEDIUMCVSS 5.4EG 5.4fixed in 10.4.14 or 11.1.1, by version range2021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that database fields used as _descriptionColumn_ are vulnerable to cross-site scripting when their content get…
- CVE-2021-21370MEDIUMCVSS 5.4EG 5.4fixed in 7.6.51, 8.7.40, 9.5.25, 10.4.14 or 11.1.1, by version range2021-03-23
vulnerable: v11.0.0, v11.1.0
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 it has been discovered that content elements of type _menu_ are vulnerable to cross-site scripting when their…
- CVE-2024-34537MEDIUMCVSS 4.9EG 4.9fixed in 13.3.1, 12.4.21, 11.5.40 or 10.4.46, by version range2024-10-28
vulnerable: v10.0.0 ... v10.4.9 (43 versions)
TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interfa…
- CVE-2024-47780LOWCVSS 3.1EG 3.1fixed in 13.3.1, 12.4.21, 11.5.40 or 10.4.46, by version range2024-10-08
vulnerable: v10.0.0 ... v10.4.9 (43 versions)
TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but …
- CVE-2025-47941HIGHCVSS 7.2EG 7.2fixed in 12.4.31 or 13.4.12, by version range2025-05-20
vulnerable: v13.0.0 ... v13.4.9 (19 versions)
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor authentication (MFA) dialog presented during backend login can b…
- CVE-2025-59014LOWCVSS 2.7EG 2.7fixed in 12.4.37 or 13.4.18, by version range2025-09-09
vulnerable: v13.0.0 ... v13.4.9 (25 versions)
An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface b…
- CVE-2025-59017HIGHCVSS 8.8EG 8.8fixed in 12.4.37 or 13.4.18, by version range2025-09-09
vulnerable: v13.0.0 ... v13.4.9 (25 versions)
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having …
- CVE-2025-59019MEDIUMCVSS 4.3EG 4.3fixed in 12.4.37 or 13.4.18, by version range2025-09-09
vulnerable: v13.0.0 ... v13.4.9 (25 versions)
Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web…
- CVE-2025-59020MEDIUMCVSS 6.5EG 6.5fixed in 14.0.2, 13.4.23, 12.4.41, 11.5.49 or 10.4.55, by version range2026-01-13
vulnerable: v10.0.0 ... v10.4.9 (43 versions)
By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for…
- CVE-2026-19418HIGHCVSS 7.3EG 7.3fixed in 13.4.342026-08-11
vulnerable: v13.0.0 ... v13.4.9 (41 versions)
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the …
- CVE-2026-47351MEDIUMCVSS 5.3EG 5.3fixed in 10.4.57, 11.5.51, 12.4.46, 13.4.31 or 14.3.3, by version range2026-06-09
vulnerable: v14.0.0 ... v14.3.2 (9 versions)
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue af…
- CVE-2026-47352MEDIUMCVSS 5.3EG 5.3fixed in 10.4.57, 11.5.51, 12.4.46, 13.4.31 or 14.3.3, by version range2026-06-09
vulnerable: v14.0.0 ... v14.3.2 (9 versions)
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS version…
- CVE-2026-6553HIGHCVSS 7.5EG 7.5fixed in 14.3.02026-04-21
vulnerable: 14.2.0, v14.2.0
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
Check whether typo3/cms-backend is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms-backend CVEs against the assets you own.
Book a Demo →