TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTypo3
APPTypo34.3.0 – 4.3.12 (excl.)4.4.0 – 4.4.9 (excl.)4.5.0 – 4.5.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2011-3583CRITICAL9.8PL ✓same product
SQL Injection w TYPO3 Core przez niepoprawne prepared statements
CVE-2026-6553HIGH7.3same product
Changing backend users' passwords via the user settings module results in storing the cleartext password in th...
CVE-2025-59022HIGH7.1same product
Backend users who had access to the recycler module could delete arbitrary data from any database table define...
CVE-2025-59018HIGH7.1same product
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0....
CVE-2025-47940HIGH7.2same product
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to vers...