Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

TYPO3 Association

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 536
32.8
VTI Score
Medium

TYPO3 Association maintains a widely deployed open-source content management system and ecosystem of extensions used across thousands of web properties, positioning it among the most prominent CMS platforms in the landscape. The vendor's vulnerability portfolio concentrates on application-layer weaknesses endemic to web frameworks, with recurring exposures spanning cross-site scripting, SQL injection, input validation flaws, and sensitive information disclosure across the core platform and community extensions such as the DAM frontend, HTML sanitizer, and discussion forum modules. The breadth of the extension ecosystem means that remediation responsibilities are distributed across both the core vendor and extension maintainers, creating complexity in coordinating and deploying fixes across heterogeneous deployments. Defenders should maintain visibility into both core TYPO3 releases and the security posture of extensions in their specific instances, as the attack surface varies significantly by configuration. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
536
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by TYPO3 Association over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Self-Reporting Analysis

Of all the CVEs published by TYPO3 Association as a CNA, 64.4% affect products that TYPO3 Association develops as a vendor.

64.4%
35.6%
Self-reported: 29 (64.4%)
Third-party: 16 (35.6%)

Of all the CVEs published that affect products developed by TYPO3 Association, 5.4% are self-published by TYPO3 Association as a CNA.

94.6%
Self-published: 29 (5.4%)
Other CNAs: 507 (94.6%)

Products(78 total)

Top CVEs

Signals from CVEs in this vendor scope (536 CVEs).

536 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-3714HIGH
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare cert
Oct 25, 20107.157NOYES
CVE-2009-0815MEDIUM
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an e
Mar 5, 20095.052NOYES
CVE-2026-49741HIGH
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Fr
Jun 9, 20268.735NONO
CVE-2019-11831CRITICAL
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a des
May 9, 20199.833NONO
CVE-2026-11607HIGH
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extensi
Jun 9, 20267.632NONO
CVE-2011-4614MEDIUM
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and develop
Feb 18, 20126.832NOYES
CVE-2009-0255HIGH
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which ma
Jan 22, 20097.532NOYES
CVE-2019-11830CRITICAL
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attack
May 9, 20199.831NONO
CVE-2010-5099MEDIUM
The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file ty
May 30, 20126.831NOYES
CVE-2026-15305MEDIUM
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced serve
Jul 14, 20266.330NONO
View all 536 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products536 CVEs
52%
42%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (0.4%)
Network161 (30.0%)
Unknown373 (69.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low156 (29.1%)
High7 (1.3%)
Unknown373 (69.6%)
User Interaction
None95 (17.7%)
Unknown373 (69.6%)
Required64 (11.9%)
Privileges Required
Low78 (14.6%)
High16 (3.0%)
None69 (12.9%)
Unknown373 (69.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (536 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
0.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
1.1% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by TYPO3 Association.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by TYPO3 Association — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For TYPO3 Association's Products

View all 5 CNAs →

Top CWEs