CVE-2026-46725
The TYPO3 "Content Element Selector" (ceselector) extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with Persistent Mode: Static in the plugin settings. This has been patched in version 3.0.3, 4.0.2, 5.0.1, and 6.0.1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-46725, https://bitbucket.org/thismaechler/typo3-ext-ceselector, https://github.com/FriendsOfPHP/security-advisories/blob/master/mmc/ceselector/CVE-2026-46725.yaml, https://typo3.org/security/advisory/typo3-ext-sa-2026-013