CVE-2025-59014
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-09

Last updated on: 2025-09-10

Assigner: TYPO3

Description
An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in the bookmark toolbar.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-09
Last Modified
2025-09-10
Generated
2026-06-16
AI Q&A
2025-09-09
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
typo3 typo3 From 11.0.0 (inc) to 11.5.48 (exc)
typo3 typo3 From 12.0.0 (inc) to 12.4.37 (exc)
typo3 typo3 From 13.0.0 (inc) to 13.4.18 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

If exploited by an administrator-level backend user, this vulnerability can cause a denial-of-service condition in the TYPO3 backend user interface, effectively blocking access and disrupting administrative operations. [1]

Executive Summary

This vulnerability is a medium-severity Denial of Service (DoS) issue in the TYPO3 CMS Bookmark Toolbar component. It occurs because of insufficient input validation, allowing an administrator-level backend user to save manipulated data in the bookmark toolbar. This triggers an uncaught exception that causes a general error state, blocking further access to the backend user interface. [1]

Detection Guidance

This vulnerability can be detected by verifying the TYPO3 CMS version in use to see if it falls within the affected ranges: 11.0.0–11.5.47, 12.0.0–12.4.36, or 13.0.0–13.4.17. Since the issue involves manipulated data in the bookmark toolbar causing a denial-of-service condition triggered by administrator-level backend users, monitoring for unusual backend UI errors or denial-of-service symptoms after bookmark toolbar changes may help detect exploitation attempts. Specific detection commands are not provided in the available resources. [1]

Mitigation Strategies

The immediate mitigation step is to update TYPO3 CMS to a fixed version: 11.5.48 ELTS, 12.4.37 LTS, or 13.4.18 LTS. This update resolves the issue by fixing the insufficient input validation in the bookmark toolbar component. Additionally, restricting administrator-level backend user access and monitoring for suspicious activity related to bookmark toolbar modifications can help reduce risk until the update is applied. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59014. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart