TYPO3 Association maintains a widely deployed open-source content management system and ecosystem of extensions used across thousands of web properties, positioning it among the most prominent CMS platforms in the landscape. The vendor's vulnerability portfolio concentrates on application-layer weaknesses endemic to web frameworks, with recurring exposures spanning cross-site scripting, SQL injection, input validation flaws, and sensitive information disclosure across the core platform and community extensions such as the DAM frontend, HTML sanitizer, and discussion forum modules. The breadth of the extension ecosystem means that remediation responsibilities are distributed across both the core vendor and extension maintainers, creating complexity in coordinating and deploying fixes across heterogeneous deployments. Defenders should maintain visibility into both core TYPO3 releases and the security posture of extensions in their specific instances, as the attack surface varies significantly by configuration. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by TYPO3 Association over time
Of all the CVEs published by TYPO3 Association as a CNA, 64.4% affect products that TYPO3 Association develops as a vendor.
Of all the CVEs published that affect products developed by TYPO3 Association, 5.4% are self-published by TYPO3 Association as a CNA.
Signals from CVEs in this vendor scope (536 CVEs).
536 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3714HIGH The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare cert | Oct 25, 2010 | 7.1 | 57 | NO | YES |
CVE-2009-0815MEDIUM The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an e | Mar 5, 2009 | 5.0 | 52 | NO | YES |
CVE-2026-49741HIGH Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Fr | Jun 9, 2026 | 8.7 | 35 | NO | NO |
CVE-2019-11831CRITICAL The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a des | May 9, 2019 | 9.8 | 33 | NO | NO |
CVE-2026-11607HIGH Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extensi | Jun 9, 2026 | 7.6 | 32 | NO | NO |
CVE-2011-4614MEDIUM PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and develop | Feb 18, 2012 | 6.8 | 32 | NO | YES |
CVE-2009-0255HIGH The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which ma | Jan 22, 2009 | 7.5 | 32 | NO | YES |
CVE-2019-11830CRITICAL PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attack | May 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2010-5099MEDIUM The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file ty | May 30, 2012 | 6.8 | 31 | NO | YES |
CVE-2026-15305MEDIUM Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced serve | Jul 14, 2026 | 6.3 | 30 | NO | NO |
Signals from CVEs in this vendor scope (536 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by TYPO3 Association.
Media articles that mention a CVE ID that affects a product developed by TYPO3 Association — matched by CVE ID, not by vendor name.