TYPO3 9.5.48

CPE Details

TYPO3 9.5.48
9.5.48
2025-09-15
15h23 +00:00
2025-09-15
15h23 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:typo3:typo3:9.5.48:*:*:*:*:*:*:*

Informations

Vendor

typo3

Product

typo3

Version

9.5.48

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-59018 2025-09-09 09h01 +00:00 Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
7.1
High
CVE-2025-59017 2025-09-09 09h01 +00:00 Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
5.3
Medium
CVE-2025-59016 2025-09-09 09h00 +00:00 Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.
5.3
Medium
CVE-2025-59013 2025-09-09 09h00 +00:00 An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a manipulated, sanitized URL.
5.3
Medium