typo3/cms-beuser
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting typo3/cms-beuserpage 1 of 1
- CVE-2024-55894MEDIUMCVSS 4.3EG 4.3✓ Fixed in 13.4.32025-01-14
vulnerable: v13.0.0 ... v13.4.2 (10 versions)
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forge…
- CVE-2025-59017HIGHCVSS 8.8EG 8.8✓ Fixed in 12.4.372025-09-09
vulnerable: v10.0.0 ... v9.5.9 (179 versions)
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having …
Check whether typo3/cms-beuser is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for typo3/cms-beuser CVEs against the assets you own.
Start Free Scan →