CVE-2025-59014Uncaught Exception in CMS

CWE-248Uncaught Exception4 documents4 sources
Severity
5.1MEDIUMNVD
EPSS
0.0%
top 94.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9

Description

An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in the bookmark toolbar.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Packages3 packages

Packagisttypo3/cms-backend11.0.012.4.37+2
NVDtypo3/typo311.0.011.5.48+2
CVEListV5typo3/typo3_cms11.0.011.5.48+2

🔴Vulnerability Details

3
CVEList
Denial of Service in TYPO3 Bookmark Toolbar2025-09-09
OSV
TYPO3 Bookmark Toolbar vulnerable to denial of service2025-09-09
GHSA
TYPO3 Bookmark Toolbar vulnerable to denial of service2025-09-09
CVE-2025-59014 — Uncaught Exception in Typo3 CMS | cvebase