Skip to content

Commit 0e38232

Browse files
authored
Merge pull request #786 from ohader/typo3/2026-06-a
Add TYPO3 CVEs for the release on 2026-06-09
2 parents aeea746 + 3d5cdb3 commit 0e38232

15 files changed

Lines changed: 243 additions & 0 deletions

‎typo3/cms-core/CVE-2026-11607.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-019: Broken Access Control in Form Framework'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-019'
3+
cve: CVE-2026-11607
4+
branches:
5+
10.x:
6+
time: '2026-06-09 09:06:07'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 09:06:07'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 09:06:07'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 09:06:07'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 09:06:07'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47343.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-007: Broken Access Control in File Abstraction Layer'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-007'
3+
cve: CVE-2026-47343
4+
branches:
5+
10.x:
6+
time: '2026-06-09 08:55:42'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 08:55:42'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 08:55:42'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 08:55:42'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 08:55:42'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47346.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-008: Broken Access Control in Form Framework'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-008'
3+
cve: CVE-2026-47346
4+
branches:
5+
10.x:
6+
time: '2026-06-09 08:56:21'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 08:56:21'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 08:56:21'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 08:56:21'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 08:56:21'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47347.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-009: Open Redirect in TYPO3 CMS'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-009'
3+
cve: CVE-2026-47347
4+
branches:
5+
10.x:
6+
time: '2026-06-09 08:57:00'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 08:57:00'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 08:57:00'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 08:57:00'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 08:57:00'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47348.yaml‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
title: 'TYPO3-CORE-SA-2026-010: Cross-Site Scripting in Indexed Search'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-010'
3+
cve: CVE-2026-47348
4+
branches:
5+
13.x:
6+
time: '2026-06-09 08:57:39'
7+
versions: ['>=13.0.0', '<13.4.31']
8+
14.x:
9+
time: '2026-06-09 08:57:39'
10+
versions: ['>=14.0.0', '<14.3.3']
11+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47349.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-011: Broken Access Control in Recycler'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-011'
3+
cve: CVE-2026-47349
4+
branches:
5+
10.x:
6+
time: '2026-06-09 08:58:19'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 08:58:19'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 08:58:19'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 08:58:19'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 08:58:19'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47350.yaml‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
title: 'TYPO3-CORE-SA-2026-012: Broken Access Control in DataHandler'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-012'
3+
cve: CVE-2026-47350
4+
branches:
5+
13.x:
6+
time: '2026-06-09 08:58:58'
7+
versions: ['>=13.0.0', '<13.4.31']
8+
14.x:
9+
time: '2026-06-09 08:58:58'
10+
versions: ['>=14.0.0', '<14.3.3']
11+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47351.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-014'
3+
cve: CVE-2026-47351
4+
branches:
5+
10.x:
6+
time: '2026-06-09 09:00:20'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 09:00:20'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 09:00:20'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 09:00:20'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 09:00:20'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-47352.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-015: Broken Access Control in Backend API'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-015'
3+
cve: CVE-2026-47352
4+
branches:
5+
10.x:
6+
time: '2026-06-09 09:01:04'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 09:01:04'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 09:01:04'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 09:01:04'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 09:01:04'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

‎typo3/cms-core/CVE-2026-49738.yaml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
title: 'TYPO3-CORE-SA-2026-016: Broken Access Control in File Abstraction Layer'
2+
link: 'https://typo3.org/security/advisory/typo3-core-sa-2026-016'
3+
cve: CVE-2026-49738
4+
branches:
5+
10.x:
6+
time: '2026-06-09 09:01:48'
7+
versions: ['<10.4.57']
8+
11.x:
9+
time: '2026-06-09 09:01:48'
10+
versions: ['>=11.0.0', '<11.5.51']
11+
12.x:
12+
time: '2026-06-09 09:01:48'
13+
versions: ['>=12.0.0', '<12.4.46']
14+
13.x:
15+
time: '2026-06-09 09:01:48'
16+
versions: ['>=13.0.0', '<13.4.31']
17+
14.x:
18+
time: '2026-06-09 09:01:48'
19+
versions: ['>=14.0.0', '<14.3.3']
20+
reference: 'composer://typo3/cms-core'

0 commit comments

Comments
 (0)