FOFA[verified]@fofabotDisclosure
The post announces the newly identified TYPO3 extension vulnerability (CVE‑2026‑46725) with a high CVSS score and potential RCE, providing alert information without evidence of exploitation or a PoC.
kokumօtօ[verified]@__kokumotoPatch
The article reports a critical remote‑code‑execution vulnerability (CVE‑2026‑46725) in the TYPO3 CMS Content Element Selector extension, noting it has already been fixed. It details the flaw involving unserializing browser cookies in Persistent Mode: Static but contains no PoC or exploit code.
Gray Hats@the_yellow_fallPatch
The tweet announces that TYPO3 has patched a critical CVE‑2026‑46725 flaw in the Content Element Selector plugin, which previously allowed unauthenticated remote code execution.
CCB Alert@CCBalertDisclosure
The tweet announces CVE‑2026‑46725—a high‑severity TYPO3 PHP deserialization flaw that allows unauthenticated remote code execution via PHP Object Injection, without providing a PoC, exploit code, or patch details.
CVE Playground@cveplaygroundPatch
A critical TYPO3 RCE vulnerability (CVE-2026-46725) has been disclosed, detailing insecure deserialization via cookie input and providing patch versions for mitigation.
moton@motonDisclosure
A critical TYPO3 extension vulnerability (CVE-2026-46725) allows unauthenticated remote code execution.
Autumn Good@autumn_good_35Patch
The advisory reports a Remote Code Execution vulnerability in the third‑party TYPO3 extension "Content Element Selector" (ceselector), with an available patch or mitigation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The brief notice announces CVE-2026-46725 as a remote code execution vulnerability caused by PHP object injection in a TYPO3 extension, without providing a PoC, exploit tool, or patch information.