CVE-2025-12998: TYPO3 Extension Modules
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5.
Affected products
- TYPO3 Extension Modules: before 4.3.11 (fixed in 4.3.11); from 5.0.0, before 5.7.4 (fixed in 5.7.4); from 6.0.0, before 6.4.2 (fixed in 6.4.2); from 7.0.0, before 7.5.5 (fixed in 7.5.5)
Published 2025-11-12. Last modified 2026-06-17.