# CVE-2025-47940

## Summary

- **CVE ID:** CVE-2025-47940
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-283
- **Published:** May 20, 2025
- **Last Modified:** Mar 13, 2026

## Description

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, administrator-level backend users without system maintainer privileges can escalate their privileges and gain system maintainer access. Exploiting this vulnerability requires a valid administrator account. Users should update to TYPO3 version 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.

## Affected Products

- TYPO3 — typo3 (>= 10.0.0, < 10.4.50)
- TYPO3 — typo3 (>= 11.0.0, < 11.5.44)
- TYPO3 — typo3 (>= 12.0.0, < 12.4.31)
- TYPO3 — typo3 (>= 13.0.0, < 13.4.12)

## References

- [CNA](https://github.com/TYPO3/typo3/security/advisories/GHSA-6frx-j292-c844)
- [CNA](https://typo3.org/security/advisory/typo3-core-sa-2025-016)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 36.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._