CVE-2024-22188: TYPO3

High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.

Affected products

  • TYPO3 TYPO3: from 8.0.0, before 8.7.57 (fixed in 8.7.57); from 9.0.0, before 9.5.46 (fixed in 9.5.46); from 10.0.0, before 10.4.43 (fixed in 10.4.43); from 11.0.0, before 11.5.35 (fixed in 11.5.35); from 12.0.0, before 12.4.11 (fixed in 12.4.11); version 13.0.0 only

Published 2024-03-05. Last modified 2026-06-17.