← Vulnerability feed

Vulnerability record · CVE-2026-6553 · published 21 April 2026

CVE-2026-6553: Typo3 cleartext storage of sensitive data vulnerability

Typo3 · Typo3

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

7.3 CVSS 4.0 High EPSS 0.27% · top 83.0% CWE-312 · Cleartext storage of sensitive data
7.3CVSS 4.0 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-6553 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-11066Typo3 mass assignment vulnerabilityIn TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on m…EPSS 1.5%10.0CVE-2009-0258Typo3 improper input validation vulnerabilityThe Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote …EPSS 3.3%9.8CVE-2011-3583Typo3 sql injection vulnerabilityIt was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a…EPSS 1.4%9.8CVE-2011-4628Typo3 improper authentication vulnerabilityTYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a …EPSS 1.6%8.8CVE-2024-55921Typo3 cross-site request forgery vulnerabilityTYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…EPSS 0.36%8.8CVE-2022-23503Typo3 code injection vulnerabilityTYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Cod…EPSS 0.81%8.8CVE-2021-41113Typo3 cross-site request forgery vulnerabilityTYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature tha…EPSS 0.64%8.8CVE-2020-15098Typo3 improper input validation vulnerabilityIn TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered th…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2026-6553), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.