cbcvebase.
CVE-2026-47350
published 2026-06-09

CVE-2026-47350: Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions…

PriorityP430medium5.3CVSS 4.0
AVNACLATNPRLUINVCNVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.24%
14.7th percentile
Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3.

Affected

4 ranges
VendorProductVersion rangeFixed in
typo3cms-core>= 13.0.0 < 13.4.3113.4.31
typo3cms-core>= 14.0.0 < 14.3.314.3.3
typo3typo3_cms>= 13.0.0 < 13.4.3113.4.31
typo3typo3_cms>= 14.0.0 < 14.3.314.3.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.