Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8x3j-439w-537c | TYPO3 Remote Code Execution in extension "Content Element Selector" (ceselector) |
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-013 |
|
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 extension "content Element Selector" |
|
| Vendors & Products |
Typo3
Typo3 extension "content Element Selector" |
Tue, 19 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with "Persistent Mode: Static" in the plugin settings. | |
| Title | Remote Code Execution in extension "Content Element Selector" (ceselector) | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-05-19T13:29:29.556Z
Reserved: 2026-05-16T09:55:27.478Z
Link: CVE-2026-46725
Updated: 2026-05-19T13:28:49.551Z
Status : Deferred
Published: 2026-05-19T10:16:25.457
Modified: 2026-06-17T10:53:52.320
Link: CVE-2026-46725
No data.
OpenCVE Enrichment
Updated: 2026-06-18T08:00:16Z
Github GHSA