Uncaught Exception Affecting typo3/cms-backend package, versions >=11.3.0, <12.4.37>=13.0.0, <13.4.18


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Uncaught Exception vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-TYPO3CMSBACKEND-12670814
  • published15 Sept 2025
  • disclosed9 Sept 2025
  • creditJakub Świes

Introduced: 9 Sep 2025

NewCVE-2025-59014  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade typo3/cms-backend to version 12.4.37, 13.4.18 or higher.

Overview

Affected versions of this package are vulnerable to Uncaught Exception via the initShortcuts function of the bookmark toolbar. An attacker can cause the backend user interface to become unresponsive by saving specially crafted data. This is only exploitable if the attacker has administrator-level backend access.

Note: Additional fixed versions are available through TYPO3’s Extended Long Term Support.

CVSS Base Scores

version 4.0
version 3.1