CVE-2026-6553: TYPO3

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

Affected products

  • TYPO3 TYPO3: version 14.2.0 only

Published 2026-04-21. Last modified 2026-06-17.