CVE-2025-59015: TYPO3
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.
Affected products
- TYPO3 TYPO3: from 12.0.0, before 12.4.37 (fixed in 12.4.37); from 13.0.0, before 13.4.18 (fixed in 13.4.18)
Published 2025-09-09. Last modified 2026-06-17.