Threat reportVulnerabilityTL-2026-2450

Swiss NCSC/NTC Pilot Project Discloses Multiple Vulnerabilities in TYPO3 CMS and QGIS/QWC2 (CVE-2025-30083, CVE-2025-11183, CVE-2025-47936, CVE-2025-47938)

criticalPATCHED

Swiss NCSC/NTC Pilot Project Discloses Multiple (TL-2026-2450), also tracked as NCSC/NTC Open Source Software Pilot Project, is a critical-severity software vulnerability, first published 2025-10-13. It has no confirmed attribution, affects coding.ms additional-tca (TYPO3 extension), references 5 CVEs (CVE-2025-30083, CVE-2025-11183, CVE-2025-47936), maps to 10 MITRE ATT&CK techniques (T1046, T1059.007, T1078), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
5Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-2450

Threat ID
TL-2026-2450
Also known as
NCSC/NTC Open Source Software Pilot Project
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, publicsector, criticalinfrastructure, technology, geospatialinformationsystems
Target regions
switzerland, Europe, Worldwide
Detection rules
9
Indicators of compromise
16

Malware and tooling in Swiss NCSC/NTC Pilot Project Discloses Multiple

Malware and tooling: QGIS Web Client 2 (QWC2), TYPO3 CMS

How Swiss NCSC/NTC Pilot Project Discloses Multiple works

Switzerland's National Cyber Security Centre (NCSC, now under the Federal Office for Cybersecurity/BACS) and the National Test Institute for Cybersecurity (NTC) ran a November 2024-June 2025 pilot combining source-code review and penetration testing of TYPO3 CMS and QGIS/QWC2, publicly disclosing on 13 October 2025 five coordinated CVEs across the two platforms (stored XSS in TYPO3's additional-tca extension, blind SSRF in TYPO3 webhooks, an unverified admin password-change flaw in TYPO3 core, and two independent stored-XSS flaws in QGIS Web Client 2 -- one in the attribute table, one in the Registration GUI) plus nine additional lower-severity findings that were fixed but never assigned public CVE identifiers.

The NCSC/NTC pilot project applied a Coordinated Vulnerability Disclosure (CVD) methodology to two widely deployed open source platforms selected by security officers from the federal government, cantons, and communes: TYPO3 (a PHP content management system) and QGIS (a geographic information system) together with its QWC2/qwc-services web client stack. NTC's technical analysis found 8 issues in TYPO3 (2 low-severity in TYPO3 Core, and 6 in extensions rated 1 critical/1 high/3 medium/1 low) and 6 issues in QGIS (1 low-severity on the QGIS server, and 5 on the QWC2 web client stack rated 2 high/3 unspecified). Of these 14 total findings, five received public CVE identifiers and detailed NTC Vulnerability Hub writeups; none of the five individually carries the pilot's single 'critical' TYPO3-extension rating (that specific finding was never assigned a CVE and remains unspecified in the public sources reviewed), and the remaining eight findings across both products were likewise fixed without public CVE assignment.

CVE-2025-30083 is a stored XSS in the 'Additional TCA' TYPO3 extension (codingms/additional-tca), versions 1.7.0-1.15.16 and 1.16.0-1.16.8. `Classes/Form/Element/BadgeSuggested.php` renders a frontend user's title into a `<a class="...">` badge without HTML encoding (`'<a class="' . $badgeClass . '" href="#" style="border-radius: 2px">' . $entry . '</a>'`); an attacker who can create a frontend/website user (e.g. `"><img onerror=alert(1) src=x>` as the title) triggers script execution when a backend editor reopens the 'Person Data' tab showing that badge. CVSS 3.1 AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:F/RL:O/RC:C, CWE-79. Fixed in 1.15.17/1.16.9 (TYPO3-EXT-SA-2025-002, credited to the Swiss NCSC Vulnerability Management Team and patch author Thomas Deuling); TYPO3 13.4+ enables backend Content Security Policy (CSP) by default as a mitigating control.

CVE-2025-47936 (TYPO3-CORE-SA-2025-012) is a blind SSRF in TYPO3's bundled webhooks system extension (ext:webhooks / typo3/cms-webhooks, `GuzzleClientFactory.php`'s `getClient()` method), affecting 12.0.0-12.4.30 and 13.0.0-13.4.11. The HTTP client factory configured request options and middleware but performed no hostname allowlist/denylist check, so an admin-level backend user configuring a webhook under System > Webhooks (triggered by an event such as a page save) could direct the server to issue requests to arbitrary hosts -- including localhost and other internal-network-only services -- effectively turning the TYPO3 server into an unauthenticated internal proxy. The response is never returned to the attacker, so the SSRF is blind (detectable only via outbound-request telemetry on the target host, not via any application response). CVSS 3.1 AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L (3.3, Low), CWE-918. Fixed in 12.4.31 LTS/13.4.12 LTS (credited to NCSC Switzerland, fix by Benjamin Franzke); mitigated pre-patch by populating `$GLOBALS['TYPO3_CONF_VARS']['HTTP']['allowed_hosts']['webhooks']`, which is unrestricted (null = allow-all) by default, or set to an empty array to block all webhook requests.

CVE-2025-47938 (TYPO3-CORE-SA-2025-013) is an unverified password-change flaw in TYPO3 core/cms-setup's backend user-management interface, affecting 9.0.0-9.5.50, 10.0.0-10.4.49, 11.0.0-11.5.43, 12.0.0-12.4.30, and 13.0.0-13.4.11. A logged-in admin editing another (or their own) backend user account through Admin Tools > Backend Users could change that user's password, disable multi-factor authentication, or create new admin accounts without re-confirming the acting user's current password -- unlike the top-menu 'change my password' widget, which did require it. This raises the impact of a hijacked or unattended admin session to full, persistent account takeover. CVSS 3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N (3.8, Low), CWE-620 (Unverified Password Change). Fixed in 9.5.51 ELTS/10.4.50 ELTS/11.5.44 ELTS/12.4.31 LTS/13.4.12 LTS (credited to NCSC Switzerland, fix by Benjamin Franzke) by introducing step-up ('sudo mode') authentication before password changes, implemented via two new PSR-14 events, `SudoModeRequiredEvent` and `SudoModeVerifyEvent`, which also let SSO-integrated deployments hook their own re-verification logic (TYPO3 change #89467).

CVE-2025-11183 is a stored XSS in QGIS Web Client 2 (QWC2), all versions before v2025.08.14. `components/LayerInfoWindow.jsx` used `dangerouslySetInnerHTML` to render attribute-table field values without sanitization; a user with layer-editing permission who draws a feature and sets its Name/Description to `<img src="x" onerror="alert(123)">` via Map Tools > Editing causes the script to execute in the browser of any other user who subsequently opens that feature's attribute table, enabling session theft or defacement. CVSS 3.1 5.2 / CVSS 4.0 6.9, CWE-79. Fixed in v2025.08.14 via DOMPurify sanitization of untrusted innerHTML (commit 764fa4e5).

CVE-2025-11184 is a second, independently discovered stored XSS in the QWC2 stack's Registration GUI module (qwc-services/qwc-registration-gui), affecting all versions up to and including v2025.03.31. `src/templates/registration.html` marked a registrable-group description field as trusted via the template engine's 'safe' filter, skipping HTML escaping entirely; an adversary with permission to edit registrable groups could set a group description to `<script>alert(document.domain)</script>`, which executes for every subsequent visitor to the public registration page. CVSS 4.0 6.9 (AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/RE:L), CWE-79. Discovered 2025-07-31, test report finalized 2025-09-12, fixed in v2025.09.30 (commit f26c420cdbf95bb427ad568cd2632d9b9a751212) by removing the 'safe' filter so default auto-escaping applies; CVE reserved by the NCSC Vulnerability Management Team on 2025-09-30, published 2025-10-13 alongside the other four.

All five CVEs were reported to the respective upstream teams within the CVD process, fixed inside the 90-day disclosure window, and published simultaneously on 13 October 2025 alongside the pilot summary and NTC's full TYPO3 and QGIS/QWC2 test reports. None of the five is listed in the CISA Known Exploited Vulnerabilities catalog, and no source reviewed reports in-the-wild exploitation; the record is a proactive coordinated-disclosure/patch-verification threat rather than an active-campaign one. NCSC/BACS stated it is evaluating a permanent, structured framework for recurring OSS security testing based on this pilot's results.

MITRE ATT&CK techniques used in TL-2026-2450

Discovery

T1046 Network Service Discovery

Execution

T1059.007 JavaScript

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1090.001 Internal Proxy

Privilege Escalation

T1098 Account Manipulation

Persistence

T1136.001 Local Account

Credential Access

T1539 Steal Web Session Cookie

Lateral Movement

T1550.004 Web Session Cookie

defense-impairment

T1556.006 Multi-Factor Authentication

Affected products and versions in Swiss NCSC/NTC Pilot Project Discloses Multiple

  • coding.ms — additional-tca (TYPO3 extension)
    Vulnerable versions: 1.7.0-1.15.16; 1.16.0-1.16.8
    Fixed in: 1.15.17; 1.16.9
  • TYPO3 Association — TYPO3 CMS (cms-core, cms-webhooks, cms-setup)
    Vulnerable versions: 9.0.0-9.5.50; 10.0.0-10.4.49; 11.0.0-11.5.43; 12.0.0-12.4.30; 13.0.0-13.4.11
    Fixed in: 9.5.51 ELTS; 10.4.50 ELTS; 11.5.44 ELTS; 12.4.31 LTS; 13.4.12 LTS
  • QGIS Project — QGIS Web Client 2 (QWC2)
    Vulnerable versions: < v2025.08.14
    Fixed in: v2025.08.14
  • qwc-services — qwc-registration-gui
    Vulnerable versions: v0.* - v2025.03.31
    Fixed in: v2025.09.30

Remediation for Swiss NCSC/NTC Pilot Project Discloses Multiple

Patches

  • additional-tca 1.15.17 / 1.16.9
  • typo3/cms-webhooks, typo3/cms-core, typo3/cms-setup: 9.5.51 ELTS / 10.4.50 ELTS / 11.5.44 ELTS / 12.4.31 LTS / 13.4.12 LTS
  • QWC2 v2025.08.14
  • qwc-registration-gui v2025.09.30 (commit f26c420cdbf95bb427ad568cd2632d9b9a751212)

Immediate actions

  • Update the additional-tca TYPO3 extension to 1.15.17 or 1.16.9 to remediate CVE-2025-30083
  • Update typo3/cms-webhooks and typo3/cms-core/cms-setup to 9.5.51 ELTS / 10.4.50 ELTS / 11.5.44 ELTS / 12.4.31 LTS / 13.4.12 LTS to remediate CVE-2025-47936 and CVE-2025-47938
  • Update QGIS Web Client 2 (QWC2) to v2025.08.14 or later to remediate CVE-2025-11183
  • Update qwc-services/qwc-registration-gui to v2025.09.30 or later to remediate CVE-2025-11184
  • Audit TYPO3 backend admin accounts created or modified around the disclosure window for unauthorized password changes, disabled MFA, or unexpected new admin accounts

Workarounds

  • TYPO3 13.4+ ships backend CSP enabled by default, reducing stored-XSS exploitability pending upgrade
  • Manually populate the webhooks allowed_hosts allowlist to block SSRF to untrusted destinations before upgrading

Longer-term hardening

  • Configure the TYPO3 webhook allowlist ($GLOBALS['TYPO3_CONF_VARS']['HTTP']['allowed_hosts']['webhooks']) to restrict outbound webhook requests to trusted hosts only, or set it to an empty array if webhooks are unused
  • Enforce least-privilege on QWC2 attribute-layer editing and registrable-group management permissions to reduce the stored-XSS attack surface
  • Enable and enforce backend Content Security Policy (CSP) on TYPO3 instances below 13.4 where it is not on by default
  • Monitor outbound HTTP requests originating from TYPO3 application hosts for connections to RFC1918/loopback destinations as a blind-SSRF indicator

CVEs associated with Swiss NCSC/NTC Pilot Project Discloses Multiple

CVE-2025-30083, CVE-2025-11183, CVE-2025-47936, CVE-2025-47938, CVE-2025-11184

Weaknesses (CWE) in Swiss NCSC/NTC Pilot Project Discloses Multiple

CWE-79, CWE-918, CWE-620

Timeline of Swiss NCSC/NTC Pilot Project Discloses Multiple

  • NCSC/NTC pilot project begins coordinated source-code review and penetration testing of TYPO3 CMS and QGIS/QWC2
  • NTC discovers the stored-XSS flaw in TYPO3's additional-tca extension (CVE-2025-30083) and the SSRF flaw in TYPO3 webhooks (CVE-2025-47936)
  • NTC privately discloses CVE-2025-30083 and CVE-2025-47936 to the TYPO3 vendor team
  • additional-tca vendor releases remediation for CVE-2025-30083 (fixed in 1.15.17/1.16.9)
  • TYPO3 releases 12.4.31 LTS / 13.4.12 LTS fixing CVE-2025-47936 (SSRF) and CVE-2025-47938 (unverified password change)
  • NCSC/NTC pilot project testing phase concludes
  • NTC privately discloses the QWC2 attribute-table stored-XSS flaw (CVE-2025-11183) to QGIS/QWC2 maintainers
  • NTC Vulnerability Hub records the discovery date for CVE-2025-11183 in the QWC2 attribute table
  • NTC discovers a second, independent QWC2-stack stored-XSS flaw in the Registration GUI module's 'safe' template filter (CVE-2025-11184)
  • QWC2 v2025.08.14 released, adding DOMPurify sanitization to fix CVE-2025-11183
  • qwc-registration-gui v2025.09.30 released (commit f26c420c), removing the unsafe template filter to fix CVE-2025-11184; CVE reserved same day
  • Coordinated public disclosure: NCSC/BACS pilot summary, full TYPO3 and QGIS/QWC2 NTC test reports, all five NTC Vulnerability Hub entries, TYPO3-EXT-SA-2025-002, TYPO3-CORE-SA-2025-012, and TYPO3-CORE-SA-2025-013 published simultaneously

Sources cited for Swiss NCSC/NTC Pilot Project Discloses Multiple

Detection coverage for TL-2026-2450

As of 2025-10-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2450 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats