Known CVE
TYPO3 ceselector Extension - Insecure Deserialization
TYPO3 extension contains a PHP Object Injection caused by passing attacker-controlled cookie to unserialize() without validation, letting remote unauthenticated attackers achieve remote code execution, exploit requires Persistent Mode: Static configuration.
CVE-2026-46725
Critical2026CVSS 9.8CWE-502
cve2026 · typo3 · deserialization · rce · ceselector · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website