Threat reportVulnerabilityTL-2026-2450
Swiss NCSC/NTC Pilot Project Discloses Multiple Vulnerabilities in TYPO3 CMS and QGIS/QWC2 (CVE-2025-30083, CVE-2025-11183, CVE-2025-47936, CVE-2025-47938)
Swiss NCSC/NTC Pilot Project Discloses Multiple (TL-2026-2450), also tracked as NCSC/NTC Open Source Software Pilot Project, is a critical-severity software vulnerability, first published 2025-10-13. It has no confirmed attribution, affects coding.ms additional-tca (TYPO3 extension), references 5 CVEs (CVE-2025-30083, CVE-2025-11183, CVE-2025-47936), maps to 10 MITRE ATT&CK techniques (T1046, T1059.007, T1078), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 5Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-2450
- Threat ID
- TL-2026-2450
- Also known as
- NCSC/NTC Open Source Software Pilot Project
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, publicsector, criticalinfrastructure, technology, geospatialinformationsystems
- Target regions
- switzerland, Europe, Worldwide
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Swiss NCSC/NTC Pilot Project Discloses Multiple
Malware and tooling: QGIS Web Client 2 (QWC2), TYPO3 CMS
How Swiss NCSC/NTC Pilot Project Discloses Multiple works
Switzerland's National Cyber Security Centre (NCSC, now under the Federal Office for Cybersecurity/BACS) and the National Test Institute for Cybersecurity (NTC) ran a November 2024-June 2025 pilot combining source-code review and penetration testing of TYPO3 CMS and QGIS/QWC2, publicly disclosing on 13 October 2025 five coordinated CVEs across the two platforms (stored XSS in TYPO3's additional-tca extension, blind SSRF in TYPO3 webhooks, an unverified admin password-change flaw in TYPO3 core, and two independent stored-XSS flaws in QGIS Web Client 2 -- one in the attribute table, one in the Registration GUI) plus nine additional lower-severity findings that were fixed but never assigned public CVE identifiers.
The NCSC/NTC pilot project applied a Coordinated Vulnerability Disclosure (CVD) methodology to two widely deployed open source platforms selected by security officers from the federal government, cantons, and communes: TYPO3 (a PHP content management system) and QGIS (a geographic information system) together with its QWC2/qwc-services web client stack. NTC's technical analysis found 8 issues in TYPO3 (2 low-severity in TYPO3 Core, and 6 in extensions rated 1 critical/1 high/3 medium/1 low) and 6 issues in QGIS (1 low-severity on the QGIS server, and 5 on the QWC2 web client stack rated 2 high/3 unspecified). Of these 14 total findings, five received public CVE identifiers and detailed NTC Vulnerability Hub writeups; none of the five individually carries the pilot's single 'critical' TYPO3-extension rating (that specific finding was never assigned a CVE and remains unspecified in the public sources reviewed), and the remaining eight findings across both products were likewise fixed without public CVE assignment.
CVE-2025-30083 is a stored XSS in the 'Additional TCA' TYPO3 extension (codingms/additional-tca), versions 1.7.0-1.15.16 and 1.16.0-1.16.8. `Classes/Form/Element/BadgeSuggested.php` renders a frontend user's title into a `<a class="...">` badge without HTML encoding (`'<a class="' . $badgeClass . '" href="#" style="border-radius: 2px">' . $entry . '</a>'`); an attacker who can create a frontend/website user (e.g. `"><img onerror=alert(1) src=x>` as the title) triggers script execution when a backend editor reopens the 'Person Data' tab showing that badge. CVSS 3.1 AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:F/RL:O/RC:C, CWE-79. Fixed in 1.15.17/1.16.9 (TYPO3-EXT-SA-2025-002, credited to the Swiss NCSC Vulnerability Management Team and patch author Thomas Deuling); TYPO3 13.4+ enables backend Content Security Policy (CSP) by default as a mitigating control.
CVE-2025-47936 (TYPO3-CORE-SA-2025-012) is a blind SSRF in TYPO3's bundled webhooks system extension (ext:webhooks / typo3/cms-webhooks, `GuzzleClientFactory.php`'s `getClient()` method), affecting 12.0.0-12.4.30 and 13.0.0-13.4.11. The HTTP client factory configured request options and middleware but performed no hostname allowlist/denylist check, so an admin-level backend user configuring a webhook under System > Webhooks (triggered by an event such as a page save) could direct the server to issue requests to arbitrary hosts -- including localhost and other internal-network-only services -- effectively turning the TYPO3 server into an unauthenticated internal proxy. The response is never returned to the attacker, so the SSRF is blind (detectable only via outbound-request telemetry on the target host, not via any application response). CVSS 3.1 AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L (3.3, Low), CWE-918. Fixed in 12.4.31 LTS/13.4.12 LTS (credited to NCSC Switzerland, fix by Benjamin Franzke); mitigated pre-patch by populating `$GLOBALS['TYPO3_CONF_VARS']['HTTP']['allowed_hosts']['webhooks']`, which is unrestricted (null = allow-all) by default, or set to an empty array to block all webhook requests.
CVE-2025-47938 (TYPO3-CORE-SA-2025-013) is an unverified password-change flaw in TYPO3 core/cms-setup's backend user-management interface, affecting 9.0.0-9.5.50, 10.0.0-10.4.49, 11.0.0-11.5.43, 12.0.0-12.4.30, and 13.0.0-13.4.11. A logged-in admin editing another (or their own) backend user account through Admin Tools > Backend Users could change that user's password, disable multi-factor authentication, or create new admin accounts without re-confirming the acting user's current password -- unlike the top-menu 'change my password' widget, which did require it. This raises the impact of a hijacked or unattended admin session to full, persistent account takeover. CVSS 3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N (3.8, Low), CWE-620 (Unverified Password Change). Fixed in 9.5.51 ELTS/10.4.50 ELTS/11.5.44 ELTS/12.4.31 LTS/13.4.12 LTS (credited to NCSC Switzerland, fix by Benjamin Franzke) by introducing step-up ('sudo mode') authentication before password changes, implemented via two new PSR-14 events, `SudoModeRequiredEvent` and `SudoModeVerifyEvent`, which also let SSO-integrated deployments hook their own re-verification logic (TYPO3 change #89467).
CVE-2025-11183 is a stored XSS in QGIS Web Client 2 (QWC2), all versions before v2025.08.14. `components/LayerInfoWindow.jsx` used `dangerouslySetInnerHTML` to render attribute-table field values without sanitization; a user with layer-editing permission who draws a feature and sets its Name/Description to `<img src="x" onerror="alert(123)">` via Map Tools > Editing causes the script to execute in the browser of any other user who subsequently opens that feature's attribute table, enabling session theft or defacement. CVSS 3.1 5.2 / CVSS 4.0 6.9, CWE-79. Fixed in v2025.08.14 via DOMPurify sanitization of untrusted innerHTML (commit 764fa4e5).
CVE-2025-11184 is a second, independently discovered stored XSS in the QWC2 stack's Registration GUI module (qwc-services/qwc-registration-gui), affecting all versions up to and including v2025.03.31. `src/templates/registration.html` marked a registrable-group description field as trusted via the template engine's 'safe' filter, skipping HTML escaping entirely; an adversary with permission to edit registrable groups could set a group description to `<script>alert(document.domain)</script>`, which executes for every subsequent visitor to the public registration page. CVSS 4.0 6.9 (AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/RE:L), CWE-79. Discovered 2025-07-31, test report finalized 2025-09-12, fixed in v2025.09.30 (commit f26c420cdbf95bb427ad568cd2632d9b9a751212) by removing the 'safe' filter so default auto-escaping applies; CVE reserved by the NCSC Vulnerability Management Team on 2025-09-30, published 2025-10-13 alongside the other four.
All five CVEs were reported to the respective upstream teams within the CVD process, fixed inside the 90-day disclosure window, and published simultaneously on 13 October 2025 alongside the pilot summary and NTC's full TYPO3 and QGIS/QWC2 test reports. None of the five is listed in the CISA Known Exploited Vulnerabilities catalog, and no source reviewed reports in-the-wild exploitation; the record is a proactive coordinated-disclosure/patch-verification threat rather than an active-campaign one. NCSC/BACS stated it is evaluating a permanent, structured framework for recurring OSS security testing based on this pilot's results.
MITRE ATT&CK techniques used in TL-2026-2450
Discovery
T1046 Network Service Discovery
Execution
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Command and Control
Privilege Escalation
Persistence
Credential Access
T1539 Steal Web Session Cookie
Lateral Movement
defense-impairment
Affected products and versions in Swiss NCSC/NTC Pilot Project Discloses Multiple
- coding.ms — additional-tca (TYPO3 extension)
Vulnerable versions: 1.7.0-1.15.16; 1.16.0-1.16.8
Fixed in: 1.15.17; 1.16.9 - TYPO3 Association — TYPO3 CMS (cms-core, cms-webhooks, cms-setup)
Vulnerable versions: 9.0.0-9.5.50; 10.0.0-10.4.49; 11.0.0-11.5.43; 12.0.0-12.4.30; 13.0.0-13.4.11
Fixed in: 9.5.51 ELTS; 10.4.50 ELTS; 11.5.44 ELTS; 12.4.31 LTS; 13.4.12 LTS - QGIS Project — QGIS Web Client 2 (QWC2)
Vulnerable versions: < v2025.08.14
Fixed in: v2025.08.14 - qwc-services — qwc-registration-gui
Vulnerable versions: v0.* - v2025.03.31
Fixed in: v2025.09.30
Remediation for Swiss NCSC/NTC Pilot Project Discloses Multiple
Patches
- additional-tca 1.15.17 / 1.16.9
- typo3/cms-webhooks, typo3/cms-core, typo3/cms-setup: 9.5.51 ELTS / 10.4.50 ELTS / 11.5.44 ELTS / 12.4.31 LTS / 13.4.12 LTS
- QWC2 v2025.08.14
- qwc-registration-gui v2025.09.30 (commit f26c420cdbf95bb427ad568cd2632d9b9a751212)
Immediate actions
- Update the additional-tca TYPO3 extension to 1.15.17 or 1.16.9 to remediate CVE-2025-30083
- Update typo3/cms-webhooks and typo3/cms-core/cms-setup to 9.5.51 ELTS / 10.4.50 ELTS / 11.5.44 ELTS / 12.4.31 LTS / 13.4.12 LTS to remediate CVE-2025-47936 and CVE-2025-47938
- Update QGIS Web Client 2 (QWC2) to v2025.08.14 or later to remediate CVE-2025-11183
- Update qwc-services/qwc-registration-gui to v2025.09.30 or later to remediate CVE-2025-11184
- Audit TYPO3 backend admin accounts created or modified around the disclosure window for unauthorized password changes, disabled MFA, or unexpected new admin accounts
Workarounds
- TYPO3 13.4+ ships backend CSP enabled by default, reducing stored-XSS exploitability pending upgrade
- Manually populate the webhooks allowed_hosts allowlist to block SSRF to untrusted destinations before upgrading
Longer-term hardening
- Configure the TYPO3 webhook allowlist ($GLOBALS['TYPO3_CONF_VARS']['HTTP']['allowed_hosts']['webhooks']) to restrict outbound webhook requests to trusted hosts only, or set it to an empty array if webhooks are unused
- Enforce least-privilege on QWC2 attribute-layer editing and registrable-group management permissions to reduce the stored-XSS attack surface
- Enable and enforce backend Content Security Policy (CSP) on TYPO3 instances below 13.4 where it is not on by default
- Monitor outbound HTTP requests originating from TYPO3 application hosts for connections to RFC1918/loopback destinations as a blind-SSRF indicator
CVEs associated with Swiss NCSC/NTC Pilot Project Discloses Multiple
CVE-2025-30083, CVE-2025-11183, CVE-2025-47936, CVE-2025-47938, CVE-2025-11184
Weaknesses (CWE) in Swiss NCSC/NTC Pilot Project Discloses Multiple
Timeline of Swiss NCSC/NTC Pilot Project Discloses Multiple
- NCSC/NTC pilot project begins coordinated source-code review and penetration testing of TYPO3 CMS and QGIS/QWC2
- NTC discovers the stored-XSS flaw in TYPO3's additional-tca extension (CVE-2025-30083) and the SSRF flaw in TYPO3 webhooks (CVE-2025-47936)
- NTC privately discloses CVE-2025-30083 and CVE-2025-47936 to the TYPO3 vendor team
- additional-tca vendor releases remediation for CVE-2025-30083 (fixed in 1.15.17/1.16.9)
- TYPO3 releases 12.4.31 LTS / 13.4.12 LTS fixing CVE-2025-47936 (SSRF) and CVE-2025-47938 (unverified password change)
- NCSC/NTC pilot project testing phase concludes
- NTC privately discloses the QWC2 attribute-table stored-XSS flaw (CVE-2025-11183) to QGIS/QWC2 maintainers
- NTC Vulnerability Hub records the discovery date for CVE-2025-11183 in the QWC2 attribute table
- NTC discovers a second, independent QWC2-stack stored-XSS flaw in the Registration GUI module's 'safe' template filter (CVE-2025-11184)
- QWC2 v2025.08.14 released, adding DOMPurify sanitization to fix CVE-2025-11183
- qwc-registration-gui v2025.09.30 released (commit f26c420c), removing the unsafe template filter to fix CVE-2025-11184; CVE reserved same day
- Coordinated public disclosure: NCSC/BACS pilot summary, full TYPO3 and QGIS/QWC2 NTC test reports, all five NTC Vulnerability Hub entries, TYPO3-EXT-SA-2025-002, TYPO3-CORE-SA-2025-012, and TYPO3-CORE-SA-2025-013 published simultaneously
Sources cited for Swiss NCSC/NTC Pilot Project Discloses Multiple
- Pilot project for testing security vulnerabilities in open source software
- Cross-Site Scripting Vulnerability in additional-tca Extension for TYPO3 (CVE-2025-30083)
- Cross-Site Scripting Vulnerability in QGIS QWC2 (CVE-2025-11183)
- Server-Side Request Forgery in TYPO3 (CVE-2025-47936)
- Unverified password change for admin users in TYPO3 (CVE-2025-47938)
- Cross-Site Scripting Vulnerability in QWC2 Registration GUI (CVE-2025-11184)
- TYPO3-EXT-SA-2025-002: Cross-Site Scripting in extension "Additional TCA"
- TYPO3-CORE-SA-2025-012: Server-Side Request Forgery via Webhooks
- TYPO3-CORE-SA-2025-013: Unverified Password Change for Backend Users
- TYPO3 CMS Webhooks Server Side Request Forgery (GHSA-p4xx-m758-3hpx)
- Unverified Password Change for Backend Users (GHSA-3jrg-97f3-rqh9)
- NVD - CVE-2025-47936 Detail
- NVD - CVE-2025-11183 Detail
- CVE-2025-11183 Impact, Exploitability, and Mitigation Steps
- CVE-2025-47936: TYPO3 CMS Webhooks SSRF Flaw
Detection coverage for TL-2026-2450
As of 2025-10-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2450 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.