1. Home
  2. Blog
  3. Typo3

Typo3

1 post tagged with “Typo3”

CVE-2026-19418: TYPO3 CMS Backend Access Control Bypass via Referrer Enforcement Failure
cvesecurityvulnerability

CVE-2026-19418: TYPO3 CMS Backend Access Control Bypass via Referrer Enforcement Failure

TYPO3 CMS 13.0.0-13.4.33 and 14.0.0-14.3.5 ship a broken referrer check that became inert when v13 moved the backend entry point to the site root. Any same-domain JavaScript can invoke backend and Install Tool endpoints with an authenticated session. Fixed in 13.4.34 and 14.3.6.

Aug 11, 2026
Read
HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.