typo3/cms-recycler
Packagist3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cms-recyclerpage 1 of 1
- CVE-2025-59017HIGHCVSS 8.8EG 8.8fixed in 12.4.37 or 13.4.18, by version range2025-09-09
vulnerable: v13.0.0 ... v13.4.9 (25 versions)
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having …
- CVE-2025-59022HIGHCVSS 8.1EG 8.1fixed in 14.0.2, 13.4.23, 12.4.41, 11.5.49 or 10.4.55, by version range2026-01-13
vulnerable: v10.0.0 ... v10.4.9 (43 versions)
Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy cr…
- CVE-2026-47349MEDIUMCVSS 5.3EG 5.3fixed in 10.4.57, 11.5.51, 12.4.46, 13.4.31 or 14.3.3, by version range2026-06-09
vulnerable: v14.0.0 ... v14.3.2 (9 versions)
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.…
Check whether typo3/cms-recycler is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms-recycler CVEs against the assets you own.
Book a Demo →