CVE-2026-46725Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with "Persistent Mode: Static" in the plugin settings.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-25)
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-05-19: 1Mentions · 2026-05-21: 2Mentions · 2026-05-25: 5Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-25: 3Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-25: 505-1905-2105-25
Signal classification2 categories
Disclosure
450.0%
Patch
450.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-191
Disclosure1
2026-05-212
Disclosure1Patch1
2026-05-255
Disclosure2Patch3
Full discourse8 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-46725 (CVSS 9.2): Unauthenticated PHP object injection in a TYPO3 extension may lead to RCE — FOFA counts indexed TYPO3 CMS surfaces, not every instance with the vulnerable extension. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJUWVBPMyI= 🎯294.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="TYPO3" 🔖Refer: https://securityonline.info/typo3-extension-content-element-selector-rce-cve-2026-46725/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces the newly identified TYPO3 extension vulnerability (CVE‑2026‑46725) with a high CVSS score and potential RCE, providing alert information without evidence of exploitation or a PoC.

    020178366.2K
    14.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    TYPO3 CMSの"Content Element Selector" (ceselector)拡張機能に重大(Critical)な脆弱性。CVE-2026-46725はCVSSスコア9.2の遠隔コード実行。ブラウザcookieをそのままPHPでunserialize()しているのが悪い。"Persistent Mode: Static"設定であることが条件。修正済み。 https://securityonline.info/typo3-extension-content-element-selector-rce-cve-2026-46725/

    Post summary

    The article reports a critical remote‑code‑execution vulnerability (CVE‑2026‑46725) in the TYPO3 CMS Content Element Selector extension, noting it has already been fixed. It details the flaw involving unserializing browser cookies in Persistent Mode: Static but contains no PoC or exploit code.

    000611.1K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    TYPO3 patches a critical 9.2 CVSS flaw (CVE-2026-46725) in Content Element Selector plugin. Unauthenticated attackers can achieve full server RCE. #TYPO3 #VulnerabilityAlert #CVE #PHPObjectInjection #RCE #CMSsecurity #SysAdmin #InfoSec #CyberSecurity https://securityonline.info/typo3-extension-content-element-selector-rce-cve-2026-46725/ https://t.co/BCrnxYIh8C

    Post summary

    The tweet announces that TYPO3 has patched a critical CVE‑2026‑46725 flaw in the Content Element Selector plugin, which previously allowed unauthenticated remote code execution.

    01051607
    12.5K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Deserialization of Untrusted Data in #TYPO3 #PHP. CVE-2026-46725 CVSS: 9.2. An unauthenticated, network-based attacker without user interaction can exploit this to trigger PHP Object Injection to execute code remotely #RCE! #Patch #Patch #Patch

    Post summary

    The tweet announces CVE‑2026‑46725—a high‑severity TYPO3 PHP deserialization flaw that allows unauthenticated remote code execution via PHP Object Injection, without providing a PoC, exploit code, or patch details.

    02021389
    7.2K followersView on X
  • CVE Playground@cveplayground
    Patch

    CVE-2026-46725: Critical TYPO3 ceselector RCE. Unsafe cookie input reaches PHP unserialize(), enabling PHP Object Injection and possible remote code execution. Patch: 6.0.1 / 5.0.1 / 4.0.2 / 3.0.3 https://cveplayground.com/blog/cve-2026-46725-typo3-ceselector-insecure-deserialization-rce?utm_source=x

    Post summary

    A critical TYPO3 RCE vulnerability (CVE-2026-46725) has been disclosed, detailing insecure deserialization via cookie input and providing patch versions for mitigation.

    0001089
    13 followersView on X
  • moton@moton
    Disclosure

    Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE • Daily CyberSecurity - https://securityonline.info/typo3-extension-content-element-selector-rce-cve-2026-46725/

    Post summary

    A critical TYPO3 extension vulnerability (CVE-2026-46725) allows unauthenticated remote code execution.

    0000097
    659 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.』 CVE-2026-46725 TYPO3-EXT-SA-2026-013: Remote Code Execution in extension "Content Element Selector" (ceselector) - TYPO3 Project https://typo3.org/security/advisory/typo3-ext-sa-2026-013

    Post summary

    The advisory reports a Remote Code Execution vulnerability in the third‑party TYPO3 extension "Content Element Selector" (ceselector), with an available patch or mitigation.

    00000344
    6.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-46725 Remote Code Execution via PHP Object Injection in TYPO3 Extension https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-46725

    Post summary

    The brief notice announces CVE-2026-46725 as a remote code execution vulnerability caused by PHP object injection in a TYPO3 extension, without providing a PoC, exploit tool, or patch information.

    0000083
    4.0K followersView on X

Explore more