PT-2026-47741 · Typo3 · Typo3/Cms

·

CVE-2026-47348

·

Published

2026-06-09

·

Updated

2026-06-12

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions TYPO3 CMS versions 13.0.0 through 13.4.30 TYPO3 CMS versions 14.0.0 through 14.3.2
Description Editors with permissions to create or modify page content can include HTML markup in page titles. These titles are stored in the search index without sanitization and are subsequently rendered without proper output encoding when displayed in frontend search results via the Indexed Search plugin. This leads to Cross-Site Scripting, a condition where malicious scripts are injected into otherwise trusted websites.
Recommendations Update TYPO3 CMS versions 13.0.0 through 13.4.30 to a version later than 13.4.30. Update TYPO3 CMS versions 14.0.0 through 14.3.2 to a version later than 14.3.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47348
GHSA-CG75-QFG2-W9HJ

Affected Products

Typo3/Cms