CVE-2025-59016: TYPO3
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.
Affected products
- TYPO3 TYPO3: from 9.0.0, before 9.5.55 (fixed in 9.5.55); from 10.0.0, up to and including 10.4.54; from 11.0.0, up to and including 11.5.48; from 12.0.0, up to and including 12.4.37; from 13.0.0, up to and including 13.4.18
Published 2025-09-09. Last modified 2026-06-17.