CVE-2026-49741 - TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework
CVE ID :CVE-2026-49741 Published : June 9, 2026, 10:54 a.m. | 21 minutes ago Description :Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence...