CVE-2026-47350: TYPO3 CMS

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.

Affected products

  • TYPO3 TYPO3 CMS: from 13.0.0, before 13.4.31 (fixed in 13.4.31); from 14.0.0, before 14.3.3 (fixed in 14.3.3)

Published 2026-06-09. Last modified 2026-07-23.