Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-47780

16
FAUCET Score

CVE-2024-47780 is a medium-severity vulnerability affecting TYPO3, an open-source Content Management Framework. Backend users could inadvertently view restricted pages in the page tree, even without proper access, if mount points were misconfigured or if pages were set to allow "everybody" access. While users could see these pages, they could not manipulate them, limiting the direct impact to information disclosure. The vulnerability has a CVSS score of 4.3 (Medium), indicating a low attack complexity and requiring low privileges, but with a limited impact on confidentiality. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Organizations are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, or 13.3.1 to remediate this issue, as no workarounds exist.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.0.0, < 10.4.46CPE matchmatch criteria
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 11.0.0, < 11.5.40CPE matchmatch criteria
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 12.0.0, < 12.4.21CPE matchmatch criteria
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 13.0.0, < 13.3.1CPE matchmatch criteria
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 29th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

composerpatch availablevia ghsa
Product: typo3/cms-backendFixed in: 13.3.1
composerpatch availablevia ghsa
Product: typo3/cms-backendFixed in: 12.4.21
composerpatch availablevia ghsa
Product: typo3/cms-backendFixed in: 11.5.40
composerpatch availablevia ghsa
Product: typo3/cms-backendFixed in: 10.4.46
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-rf5m-h8q9-9w6qlow

Information Disclosure in TYPO3 Page Tree

Oct 8, 2024

References

github.com / TYPO3/typo3/security/advisories/GHSA-rf5m-h8q9-9w6q
Vendor Advisory
typo3.org / security/advisory/typo3-core-sa-2024-012
Vendor Advisory