TYPO3 Association
First CVE: Jul 22, 2025Active for: 1 year
45
CVEs Published
More CVEs Published than 55% of tracked CNAs
22.5
Avg CVEs / Year
More Avg CVEs / Year than 71% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 17% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by TYPO3 Association as a CNA, 64.4% affect products that TYPO3 Association develops as a vendor.
64.4%
35.6%
Self-reported: 29Third-party: 16
Of all the CVEs published that affect products developed by TYPO3 Association, 5.4% are self-published by TYPO3 Association as a CNA.
94.6%
Self-published: 29Published by other CNAs: 507
Trends Over Time
The number and severity of CVEs published by TYPO3 Association over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2025
12 months ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by TYPO3 Association as a CNA, regardless of affected vendor or product.
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46725CRITICAL The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted seri | May 19, 2026 | 9.2 | 49 | NO | YES |
CVE-2026-49741HIGH Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Fr | Jun 9, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-11607HIGH Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extensi | Jun 9, 2026 | 7.6 | 32 | NO | NO |
CVE-2026-8827HIGH The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within | May 19, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-8726HIGH The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter o | May 19, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-15305MEDIUM Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced serve | Jul 14, 2026 | 6.3 | 30 | NO | NO |
CVE-2026-49742HIGH Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback stor | Jun 9, 2026 | 7.1 | 30 | NO | NO |
CVE-2026-47346HIGH Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. | Jun 9, 2026 | 7.6 | 30 | NO | NO |
CVE-2026-4208HIGH The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty st | Mar 17, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-47343HIGH Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to mis | Jun 9, 2026 | 7.2 | 29 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA45 CVEs
9%
53%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (6.7%)
Network42 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (97.8%)
High1 (2.2%)
Unknown0 (0.0%)
User Interaction
None38 (84.4%)
Unknown0 (0.0%)
Required1 (2.2%)
Privileges Required
Low27 (60.0%)
High7 (15.6%)
None11 (24.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.2% of CVEs· 86th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by TYPO3 Association as a CNA.
Media Mentions
Media articles that mention a CVE ID published by TYPO3 Association as a CNA — matched by CVE ID, not by organization name.