typo3/cms-workspaces
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cms-workspacespage 1 of 1
- CVE-2025-59017HIGHCVSS 8.8EG 8.8✓ Fixed in 12.4.372025-09-09
vulnerable: v10.0.0 ... v9.5.9 (179 versions)
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having …
- CVE-2025-59018MEDIUMCVSS 6.5EG 6.5✓ Fixed in 12.4.372025-09-09
vulnerable: v10.0.0 ... v9.5.9 (179 versions)
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend rou…
Check whether typo3/cms-workspaces is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms-workspaces CVEs against the assets you own.
Start Free Scan →