CVE-2026-47349: TYPO3 CMS

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

Affected products

  • TYPO3 TYPO3 CMS: before 10.4.57 (fixed in 10.4.57); from 11.0.0, before 11.5.51 (fixed in 11.5.51); from 12.0.0, before 12.4.46 (fixed in 12.4.46); from 13.0.0, before 13.4.31 (fixed in 13.4.31); from 14.0.0, before 14.3.3 (fixed in 14.3.3)

Published 2026-06-09. Last modified 2026-07-23.