CVE-2025-47938

TYPO3 Vulnerable to Unverified Password Change for Backend Users

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current password. When an administrator updates their own account or modifies other user accounts via the admin interface, the current password is not requested for verification. This behavior may lower the protection against unauthorized access in scenarios where an admin session is hijacked or left unattended, as it enables password changes without additional authentication. Users should update to TYPO3 version 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.


We have discovered 3 live websites that are affected by CVE-2025-47938.

Run a Free Instant Scan




Affected Software

Product  TYPO3 CMS
Category Content Management System
Vulnerable Domains3 live websites (less than 0.1% of TYPO3 CMS install base)
Vulnerable Versions
  • from 9 through 9.5.51
  • from 10 through 10.4.50
  • from 11 through 11.5.44
  • from 12 through 12.4.31
  • from 13 through 13.4.12
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-620 Unverified Password Change



Details

  • Published - May 20, 2025
  • Updated - May 20, 2025

Website Distribution by Country

Number of websites using CVE-2025-47938
United States2 websites



Germany1 websites

Website Distribution by TLD

Number of websites using CVE-2025-47938
.ca2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-47938

Top websites that are affected by CVE-2025-47938. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.ca United States**,***,***
*************.biz Germany**,***,***
*********.ca United States**,***,***
See full domain list

FAQ

CVE-2025-47938 is Unverified Password Change in TYPO3 CMS
A total of 3 websites have been identified as vulnerable to CVE-2025-47938, based on global website indexing conducted by WebTechSurvey.
The TYPO3 CMS is affected by the CVE-2025-47938 vulnerability.
TYPO3 CMS versions up to 13.4.12 are vulnerable to CVE-2025-47938.
CVE-2025-47938 is resolved in version 13.4.12 of TYPO3 CMS.