Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xvv6-p4wf-mvx7 | TYPO3 CMS Stores Cleartext Password in User Settings Module |
Tue, 05 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:typo3:typo3:14.2.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 21 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0. | |
| Title | TYPO3 CMS Stores Cleartext Password in User Settings Module | |
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Weaknesses | CWE-312 | |
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-04-21T13:20:23.515Z
Reserved: 2026-04-17T21:40:53.165Z
Link: CVE-2026-6553
Updated: 2026-04-21T13:20:18.344Z
Status : Analyzed
Published: 2026-04-21T10:16:31.220
Modified: 2026-05-05T19:49:37.337
Link: CVE-2026-6553
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:46:37Z
Github GHSA