CVE-2025-59019: TYPO3
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having access to them.
Affected products
- TYPO3 TYPO3: from 11.0.0, before 11.5.48 (fixed in 11.5.48); from 12.0.0, before 12.4.37 (fixed in 12.4.37); from 13.0.0, before 13.4.18 (fixed in 13.4.18)
Published 2025-09-09. Last modified 2026-06-17.