CVE-2025-47940 Details
Description
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update to TYPO3 version 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.
A privilege escalation vulnerability has been identified in TYPO3 versions 10.4.0 prior to 10.4.50 ELTS, 11.0.0 prior to 11.5.44 ELTS, 12.0.0 prior to 12.4.30, and 13.0.0 prior to 13.4.11. This vulnerability allows administrator-level backend users without system maintainer privileges to escalate their privileges and gain system maintainer access. Exploitation requires a valid administrator account.
Users are advised to update TYPO3 to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TYPO3/typo3/security/advisories/GHSA-6frx-j292-c844 | [email protected] | Vendor Advisory |
| https://typo3.org/security/advisory/typo3-core-sa-2025-016 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-283 | Unverified Ownership | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| typo3 typo3 | >= 10.4.0, < 10.4.50 >= 11.0.0, < 11.5.44 >= 12.0.0, < 12.4.31 >= 13.0.0, < 13.4.12 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2025 | Initial Analysis | [email protected] |
| May 20, 2025 | New CVE Received | [email protected] |