{"id":"CVE-2025-47940","aliases":["GHSA-6frx-j292-c844"],"url":"https://o3.security/vulnerability/CVE-2025-47940","summary":"TYPO3 CMS Vulnerable to Privilege Escalation to System Maintainer","details":"TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update to TYPO3 version 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.","published":"2025-05-20T14:06:07.374Z","modified":"2026-08-27T03:30:23.880331808Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00437,"percentile":0.37247,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"10.4.50"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"11.5.44"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.31"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"13.4.12"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47940.json"},{"type":"ADVISORY","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-6frx-j292-c844"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47940"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2025-016"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:30:23.880331808Z"}}