CVE-2026-47348: TYPO3 CMS
Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.
Affected products
- TYPO3 TYPO3 CMS: from 13.0.0, before 13.4.31 (fixed in 13.4.31); from 14.0.0, before 14.3.3 (fixed in 14.3.3)
Published 2026-06-09. Last modified 2026-07-23.