5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
Basic Information
ID
CVE-2026-47349
Source
TYPO3
Published
Jun 9, 2026 at 10:51
Affected Product
Vendor
TYPO3
Product
TYPO3 CMS
Affected Versions
TYPO3 TYPO3 CMS 0
TYPO3 TYPO3 CMS 11.0.0
TYPO3 TYPO3 CMS 12.0.0
TYPO3 TYPO3 CMS 13.0.0
TYPO3 TYPO3 CMS 14.0.0
TYPO3 TYPO3 CMS 11.0.0
TYPO3 TYPO3 CMS 12.0.0
TYPO3 TYPO3 CMS 13.0.0
TYPO3 TYPO3 CMS 14.0.0