CVE-2026-6553: TYPO3
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
Affected products
- TYPO3 TYPO3: version 14.2.0 only
Published 2026-04-21. Last modified 2026-06-17.