CVE-2026-56095: TYPO3 Extension Apache Solr For TYPO3 - Enterprise Search

High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If user-generated content saved in the TYPO3 database can reach an indexed field, this exposes a PHP Object Injection surface.

Affected products

  • TYPO3 Extension Apache Solr For TYPO3 - Enterprise Search: from 13.0.0, before 13.1.4 (fixed in 13.1.4); from 12.0.0, before 12.1.4 (fixed in 12.1.4); from 11.5.0, before 11.6.6 (fixed in 11.6.6)

Published 2026-08-25. Last modified 2026-09-17.