CVE-2026-47347EPSS p37.8%

CVE-2026-47347CVE-2026-47347

Description

Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks if the URL is used after it has passed the aforementioned sanitization checks. This enables attackers to redirect users to external content and carry out phishing attacks. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

Scoring

EPSS0.48% probability of exploitation · percentile 37.8% · 2026-06-19T12:03:05Z
Last modified2026-06-09

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-47345
CVE
CVE-2026-47348
CVE
CVE-2026-47343
CVE
CVE-2026-47344
CVE
CVE-2026-47351
CVE
CVE-2026-47352
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.