CVE-2025-47939

TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context. This lack of restriction means it is possible to upload files that may be considered potentially harmful, such as executable binaries (e.g., `.exe` files), or files with inconsistent file extensions and MIME types (for example, a file incorrectly named with a `.png` extension but actually carrying the MIME type `application/zip`) starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS. Although such files are not directly executable through the web server, their presence can introduce indirect risks. For example, third-party services such as antivirus scanners or malware detection systems might flag or block access to the website for end users if suspicious files are found. This could negatively affect the availability or reputation of the site. Users should update to TYPO3 version 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.


We have discovered 4 live websites that are affected by CVE-2025-47939.

Run a Free Instant Scan




Affected Software

Product  TYPO3 CMS
Category Content Management System
Vulnerable Domains4 live websites (less than 0.1% of TYPO3 CMS install base)
Vulnerable Versions
  • from 9 through 9.5.51
  • from 10 through 10.4.50
  • from 11 through 11.5.44
  • from 12 through 12.4.31
  • from 13 through 13.4.12
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-351 Insufficient Type Distinction



Details

  • Published - May 20, 2025
  • Updated - May 20, 2025

Website Distribution by Country

Number of websites using CVE-2025-47939
United States2 websites



Czech Republic1 websites
Germany1 websites

Website Distribution by TLD

Number of websites using CVE-2025-47939
.ca2 websites
.cz1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-47939

Top websites that are affected by CVE-2025-47939. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.ca United States**,***,***
***********.cz Czech Republic**,***,***
*************.biz Germany**,***,***
*********.ca United States**,***,***
See full domain list

FAQ

CVE-2025-47939 is Insufficient Type Distinction in TYPO3 CMS
A total of 4 websites have been identified as vulnerable to CVE-2025-47939, based on global website indexing conducted by WebTechSurvey.
The TYPO3 CMS is affected by the CVE-2025-47939 vulnerability.
TYPO3 CMS versions up to 13.4.12 are vulnerable to CVE-2025-47939.
CVE-2025-47939 is resolved in version 13.4.12 of TYPO3 CMS.