Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-47347

26
FAUCET Score

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

First published: Jun 9, 2026Last modified: Jun 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 10.4.57CPE match
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 11.0.0, < 11.5.51CPE match
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 12.0.0, < 12.4.46CPE match
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 13.0.0, < 13.4.31CPE match
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
>= 14.0.0, < 14.3.3CPE match
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 22nd percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

composerpatch availablevia ghsa
Product: typo3/cms-coreFixed in: 10.4.57
composerpatch availablevia ghsa
Product: typo3/cms-coreFixed in: 11.5.51
composerpatch availablevia ghsa
Product: typo3/cms-coreFixed in: 12.4.46
composerpatch availablevia ghsa
Product: typo3/cms-coreFixed in: 13.4.31
composerpatch availablevia ghsa
Product: typo3/cms-coreFixed in: 14.3.3

Vendor Advisories (1)

composerGHSA-3p42-w5ch-gg42medium

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

Jun 12, 2026

References

github.com / TYPO3/typo3/commit/22c2dd5398ebc4cb7aa4aa37e02cb39181dee0cd
github.com / TYPO3/typo3/commit/3ffc0835012c6199db0e1dc4b56a77147d8600e0
typo3.org / security/advisory/typo3-core-sa-2026-009