Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4241 articles · 196928 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-56095PATCHED
typo3 · extension "apache solr for typo3 - enterprise search"

Insecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

Description

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If user-generated content saved in the TYPO3 database can reach an indexed field, this exposes a PHP Object Injection surface.

Affected Products

VendorProductVersions
typo3extension "apache solr for typo3 - enterprise search"13.0.0, 12.0.0, 0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-025(vendor-advisory)

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-56095 | TYPO3 Apache Solr for TYPO3 Extension up to 11.6.5/12.1.3/13.1.3 Indexer unserialize deserialization
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
13.1.412.1.411.6.6
CWECWE-502
PublishedAug 25, 2026
Trending Score25
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77136EXPKEV
Server-Side Template Injection in extension "powermail" (powermail)
Trending: 92
NONECVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
Trending: 34
NONECVE-2026-77143
Broken Access Control in extension "Forum" (pforum)
Trending: 29
NONECVE-2026-77141
Broken Access Control in extension "Club Directory" (clubdirectory)
Trending: 29
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026