CVE Explorer
CVE-2026-15305
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the MimeTypeValidator was registered during form building before concrete form definition properties were applied, resulting in the validator never being added to the processing pipeline. This issue affects TYPO3 CMS versions 14.2.0-14.3.4.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://packagist.org","defaultStatus":"unaffected","modules":["Form Framework"],"packageName":"typo3/cms-form","product":"TYPO3 CMS","repo":"https://github.com/TYPO3/typo3","vendor":"TYPO3","versions":[{"lessThan":"14.3.5","status":"affected","version":"14.2.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:76f5d692b1cfa5df99893f81b530cf4d88974090fad79c173dc49edeb979edbd · sha256:5d1b3b4afe2e2f7a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:76f5d692b1cfa5df99893f81b530cf4d88974090fad79c173dc49edeb979edbd · sha256:5d1b3b4afe2e2f7a… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-351","description":"CWE-351 Insufficient Type Distinction","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:76f5d692b1cfa5df99893f81b530cf4d88974090fad79c173dc49edeb979edbd · sha256:5d1b3b4afe2e2f7a… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"Git commit of main branch","tags":["patch"],"url":"https://github.com/TYPO3/typo3/commit/817ad41cc9dd28aac0fc4d0fe16fc25d46dd554a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:76f5d692b1cfa5df99893f81b530cf4d88974090fad79c173dc49edeb979edbd · sha256:5d1b3b4afe2e2f7a… · /containers/cna/references/1
{"name":"Git commit of 14.3 branch","tags":["patch"],"url":"https://github.com/TYPO3/typo3/commit/cfda21050398eb145211a4fa6f9988f10e43e10b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:76f5d692b1cfa5df99893f81b530cf4d88974090fad79c173dc49edeb979edbd · sha256:5d1b3b4afe2e2f7a… · /containers/cna/references/2
{"tags":["vendor-advisory"],"url":"https://typo3.org/security/advisory/typo3-core-sa-2026-020"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:76f5d692b1cfa5df99893f81b530cf4d88974090fad79c173dc49edeb979edbd · sha256:5d1b3b4afe2e2f7a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.