TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands
It has been discovered that TYPO3 CMS is susceptible to unauthorized modification of system-wide configuration.
Read moreTYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2026-019: Broken Access Control in Form Framework
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-018: Insecure Deserialization in Core API
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-017: Privilege Escalation & SQL Injection in Form Framework
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-016: Broken Access Control in File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-015: Broken Access Control in Backend API
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard
It has been discovered that TYPO3 CMS is susceptible to broken access control.