CVE 9.2 CRITICAL

Remote Code Execution in extension “Content Element Selector” (ceselector)_CVE-2026-46725

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with "Persistent Mode: Static" in the plugin settings.

AI Analysis

Remote Code Execution vulnerability in the Content Element Selector extension due to insufficient input validation, allowing an attacker to execute arbitrary code on the TYPO3 server.

Basic Information

ID CVE-2026-46725
Source TYPO3
Published May 19, 2026 at 09:25

Affected Product

Vendor TYPO3
Product Extension "Content Element Selector"
Version 6.0.0, 5.0.0, 4.0.0, 0
Affected Versions TYPO3 Extension "Content Element Selector" 6.0.0
TYPO3 Extension "Content Element Selector" 5.0.0
TYPO3 Extension "Content Element Selector" 4.0.0
TYPO3 Extension "Content Element Selector" 0

CWE Classification

AI Assessment

AI Score 9.2 / 10
AI Severity Critical
Vendor TYPO3
Product Content Element Selector
Version 6.0.0, 5.0.0, 4.0.0, 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.