CVE-2018-6905: TYPO3

Medium severity, CVSS 4.8. EPSS: 2.2% chance of exploitation in the next 30 days.

The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.

Affected products

  • TYPO3 TYPO3: before 8.7.11 (fixed in 8.7.11); from 9.0.0, before 9.1.0 (fixed in 9.1.0)

Published 2018-04-08. Last modified 2026-06-17.