TYPO3 Association

First CVE: Jul 22, 2025Active for: 1 year
45
CVEs Published
More CVEs Published than 55% of tracked CNAs
22.5
Avg CVEs / Year
More Avg CVEs / Year than 71% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 17% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by TYPO3 Association as a CNA, 64.4% affect products that TYPO3 Association develops as a vendor.

64.4%
35.6%
Self-reported: 29Third-party: 16

Of all the CVEs published that affect products developed by TYPO3 Association, 5.4% are self-published by TYPO3 Association as a CNA.

94.6%
Self-published: 29Published by other CNAs: 507

Trends Over Time

The number and severity of CVEs published by TYPO3 Association over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2025
12 months ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by TYPO3 Association as a CNA, regardless of affected vendor or product.

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted seri
May 19, 20269.249NOYES
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Fr
Jun 9, 20268.735NONO
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extensi
Jun 9, 20267.632NONO
The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within
May 19, 20268.231NONO
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter o
May 19, 20268.231NONO
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced serve
Jul 14, 20266.330NONO
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback stor
Jun 9, 20267.130NONO
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction.
Jun 9, 20267.630NONO
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty st
Mar 17, 20268.830NONO
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to mis
Jun 9, 20267.229NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA45 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local3 (6.7%)
Network42 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (97.8%)
High1 (2.2%)
Unknown0 (0.0%)
User Interaction
None38 (84.4%)
Unknown0 (0.0%)
Required1 (2.2%)
Privileges Required
Low27 (60.0%)
High7 (15.6%)
None11 (24.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.2% of CVEs· 86th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by TYPO3 Association as a CNA.

Media Mentions

Media articles that mention a CVE ID published by TYPO3 Association as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs