GHSA-cg75-qfg2-w9hj

Suggest an improvement
Source
https://github.com/advisories/GHSA-cg75-qfg2-w9hj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cg75-qfg2-w9hj/GHSA-cg75-qfg2-w9hj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cg75-qfg2-w9hj
Aliases
Published
2026-06-12T19:06:52Z
Modified
2026-09-10T03:51:08Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
TYPO3 CMS has Cross-Site Scripting in Indexed Search
Details

Problem

Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability.

Solution

Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described.

Credits

TYPO3 CMS thanks Jan Kahmen and Sanjay Singh Jhala for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it.

Resources

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-12T19:06:52Z",
    "nvd_published_at": "2026-06-09T11:16:52Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.0.0
Fixed
13.4.31

Affected versions

v13.*
v13.0.0
v13.0.1
v13.1.0
v13.1.1
v13.2.0
v13.2.1
v13.3.0
v13.3.1
v13.4.0
v13.4.1
v13.4.2
v13.4.3
v13.4.4
v13.4.5
v13.4.6
v13.4.7
v13.4.8
v13.4.9
v13.4.10
v13.4.11
v13.4.12
v13.4.13
v13.4.14
v13.4.15
v13.4.16
v13.4.17
v13.4.18
v13.4.19
v13.4.20
v13.4.21
v13.4.22
v13.4.23
v13.4.24
v13.4.25
v13.4.26
v13.4.27
v13.4.28
v13.4.29
v13.4.30

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cg75-qfg2-w9hj/GHSA-cg75-qfg2-w9hj.json"

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0.0
Fixed
14.3.3

Affected versions

v14.*
v14.0.0
v14.0.1
v14.0.2
v14.1.0
v14.1.1
v14.2.0
v14.3.0
v14.3.1
v14.3.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cg75-qfg2-w9hj/GHSA-cg75-qfg2-w9hj.json"

Packagist / typo3/cms-indexed-search

Package

Name
typo3/cms-indexed-search
Purl
pkg:composer/typo3/cms-indexed-search

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.0.0
Fixed
13.4.31

Affected versions

v13.*
v13.0.0
v13.0.1
v13.1.0
v13.1.1
v13.2.1
v13.3.0
v13.3.1
v13.4.0
v13.4.1
v13.4.2
v13.4.3
v13.4.4
v13.4.5
v13.4.6
v13.4.7
v13.4.8
v13.4.9
v13.4.10
v13.4.11
v13.4.12
v13.4.13
v13.4.14
v13.4.15
v13.4.16
v13.4.17
v13.4.18
v13.4.19
v13.4.20
v13.4.21
v13.4.22
v13.4.23
v13.4.24
v13.4.25
v13.4.26
v13.4.27
v13.4.28
v13.4.29
v13.4.30

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cg75-qfg2-w9hj/GHSA-cg75-qfg2-w9hj.json"

Packagist / typo3/cms-indexed-search

Package

Name
typo3/cms-indexed-search
Purl
pkg:composer/typo3/cms-indexed-search

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0.0
Fixed
14.3.3

Affected versions

v14.*
v14.0.0
v14.0.1
v14.0.2
v14.1.0
v14.1.1
v14.2.0
v14.3.0
v14.3.1
v14.3.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cg75-qfg2-w9hj/GHSA-cg75-qfg2-w9hj.json"