# Swiss NCSC/NTC Pilot Project Discloses Multiple Vulnerabilities in TYPO3 CMS and QGIS/QWC2 (CVE-2025-30083, CVE-2025-11183, CVE-2025-47936, CVE-2025-47938)

> Switzerland's National Cyber Security Centre (NCSC, now under the Federal Office for Cybersecurity/BACS) and the National Test Institute for Cybersecurity (NTC) ran a November 2024-June 2025 pilot combining source-code review and penetration testing of TYPO3 CMS and QGIS/QWC2, publicly disclosing on 13 October 2025 five coordinated CVEs across the two platforms (stored XSS in TYPO3's additional-tca extension, blind SSRF in TYPO3 webhooks, an unverified admin password-change flaw in TYPO3 core, and two independent stored-XSS flaws in QGIS Web Client 2 -- one in the attribute table, one in the Registration GUI) plus nine additional lower-severity findings that were fixed but never assigned public CVE identifiers.

- **Published:** 2025-10-13T00:00:00Z
- **Last reviewed:** 2025-10-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2450
- **ID:** TL-2026-2450
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-30083, CVE-2025-11183, CVE-2025-47936, CVE-2025-47938, CVE-2025-11184

## Description

The NCSC/NTC pilot project applied a Coordinated Vulnerability Disclosure (CVD) methodology to two widely deployed open source platforms selected by security officers from the federal government, cantons, and communes: TYPO3 (a PHP content management system) and QGIS (a geographic information system) together with its QWC2/qwc-services web client stack. NTC's technical analysis found 8 issues in TYPO3 (2 low-severity in TYPO3 Core, and 6 in extensions rated 1 critical/1 high/3 medium/1 low) and 6 issues in QGIS (1 low-severity on the QGIS server, and 5 on the QWC2 web client stack rated 2 high/3 unspecified). Of these 14 total findings, five received public CVE identifiers and detailed NTC Vulnerability Hub writeups; none of the five individually carries the pilot's single 'critical' TYPO3-extension rating (that specific finding was never assigned a CVE and remains unspecified in the public sources reviewed), and the remaining eight findings across both products were likewise fixed without public CVE assignment.

CVE-2025-30083 is a stored XSS in the 'Additional TCA' TYPO3 extension (codingms/additional-tca), versions 1.7.0-1.15.16 and 1.16.0-1.16.8. `Classes/Form/Element/BadgeSuggested.php` renders a frontend user's title into a `<a class="...">` badge without HTML encoding (`'<a class="' . $badgeClass . '" href="#" style="border-radius: 2px">' . $entry . '</a>'`); an attacker who can create a frontend/website user (e.g. `"><img onerror=alert(1) src=x>` as the title) triggers script execution when a backend editor reopens the 'Person Data' tab showing that badge. CVSS 3.1 AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:F/RL:O/RC:C, CWE-79. Fixed in 1.15.17/1.16.9 (TYPO3-EXT-SA-2025-002, credited to the Swiss NCSC Vulnerability Management Team and patch author Thomas Deuling); TYPO3 13.4+ enables backend Content Security Policy (CSP) by default as a mitigating control.

CVE-2025-47936 (TYPO3-CORE-SA-2025-012) is a blind SSRF in TYPO3's bundled webhooks system extension (ext:webhooks / typo3/cms-webhooks, `GuzzleClientFactory.php`'s `getClient()` method), affecting 12.0.0-12.4.30 and 13.0.0-13.4.11. The HTTP client factory configured request options and middleware but performed no hostname allowlist/denylist check, so an admin-level backend user configuring a webhook under System > Webhooks (triggered by an event such as a page save) could direct the server to issue requests to arbitrary hosts -- including localhost and other internal-network-only services -- effectively turning the TYPO3 server into an unauthenticated internal proxy. The response is never returned to the attacker, so the SSRF is blind (detectable only via outbound-request telemetry on the target host, not via any application response). CVSS 3.1 AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L (3.3, Low), CWE-918. Fixed in 12.4.31 LTS/13.4.12 LTS (credited to NCSC Switzerland, fix by Benjamin Franzke); mitigated pre-patch by populating `$GLOBALS['TYPO3_CONF_VARS']['HTTP']['allowed_hosts']['webhooks']`, which is unrestricted (null = allow-all) by default, or set to an empty array to block all webhook requests.

CVE-2025-47938 (TYPO3-CORE-SA-2025-013) is an unverified password-change flaw in TYPO3 core/cms-setup's backend user-management interface, affecting 9.0.0-9.5.50, 10.0.0-10.4.49, 11.0.0-11.5.43, 12.0.0-12.4.30, and 13.0.0-13.4.11. A logged-in admin editing another (or their own) backend user account through Admin Tools > Backend Users could change that user's password, disable multi-factor authentication, or create new admin accounts without re-confirming the acting user's current password -- unlike the top-menu 'change my password' widget, which did require it. This raises the impact of a hijacked or unattended admin session to full, persistent account takeover. CVSS 3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N (3.8, Low), CWE-620 (Unverified Password Change). Fixed in 9.5.51 ELTS/10.4.50 ELTS/11.5.44 ELTS/12.4.31 LTS/13.4.12 LTS (credited to NCSC Switzerland, fix by Benjamin Franzke) by introducing step-up ('sudo mode') authentication before password changes, implemented via two new PSR-14 events, `SudoModeRequiredEvent` and `SudoModeVerifyEvent`, which also let SSO-integrated deployments hook their own re-verification logic (TYPO3 change #89467).

CVE-2025-11183 is a stored XSS in QGIS Web Client 2 (QWC2), all versions before v2025.08.14. `components/LayerInfoWindow.jsx` used `dangerouslySetInnerHTML` to render attribute-table field values without sanitization; a user with layer-editing permission who draws a feature and sets its Name/Description to `<img src="x" onerror="alert(123)">` via Map Tools > Editing causes the script to execute in the browser of any other user who subsequently opens that feature's attribute table, enabling session theft or defacement. CVSS 3.1 5.2 / CVSS 4.0 6.9, CWE-79. Fixed in v2025.08.14 via DOMPurify sanitization of untrusted innerHTML (commit 764fa4e5).

CVE-2025-11184 is a second, independently discovered stored XSS in the QWC2 stack's Registration GUI module (qwc-services/qwc-registration-gui), affecting all versions up to and including v2025.03.31. `src/templates/registration.html` marked a registrable-group description field as trusted via the template engine's 'safe' filter, skipping HTML escaping entirely; an adversary with permission to edit registrable groups could set a group description to `<script>alert(document.domain)</script>`, which executes for every subsequent visitor to the public registration page. CVSS 4.0 6.9 (AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/RE:L), CWE-79. Discovered 2025-07-31, test report finalized 2025-09-12, fixed in v2025.09.30 (commit f26c420cdbf95bb427ad568cd2632d9b9a751212) by removing the 'safe' filter so default auto-escaping applies; CVE reserved by the NCSC Vulnerability Management Team on 2025-09-30, published 2025-10-13 alongside the other four.

All five CVEs were reported to the respective upstream teams within the CVD process, fixed inside the 90-day disclosure window, and published simultaneously on 13 October 2025 alongside the pilot summary and NTC's full TYPO3 and QGIS/QWC2 test reports. None of the five is listed in the CISA Known Exploited Vulnerabilities catalog, and no source reviewed reports in-the-wild exploitation; the record is a proactive coordinated-disclosure/patch-verification threat rather than an active-campaign one. NCSC/BACS stated it is evaluating a permanent, structured framework for recurring OSS security testing based on this pilot's results.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059.007 JavaScript
- T1136.001 Local Account
- T1098 Account Manipulation
- T1556.006 Multi-Factor Authentication
- T1539 Steal Web Session Cookie
- T1046 Network Service Discovery
- T1550.004 Web Session Cookie
- T1090.001 Internal Proxy

## Sources

- [Pilot project for testing security vulnerabilities in open source software](https://www.bacs.admin.ch/25-ntc-oss-en)
- [Cross-Site Scripting Vulnerability in additional-tca Extension for TYPO3 (CVE-2025-30083)](https://hub.ntc.swiss/ntcf-2025-1294)
- [Cross-Site Scripting Vulnerability in QGIS QWC2 (CVE-2025-11183)](https://hub.ntc.swiss/ntcf-2025-4286)
- [Server-Side Request Forgery in TYPO3 (CVE-2025-47936)](https://hub.ntc.swiss/ntcf-2025-3379)
- [Unverified password change for admin users in TYPO3 (CVE-2025-47938)](https://hub.ntc.swiss/ntcf-2025-6472)
- [Cross-Site Scripting Vulnerability in QWC2 Registration GUI (CVE-2025-11184)](https://hub.ntc.swiss/ntcf-2025-7724)
- [TYPO3-EXT-SA-2025-002: Cross-Site Scripting in extension "Additional TCA"](https://typo3.org/security/advisory/typo3-ext-sa-2025-002)
- [TYPO3-CORE-SA-2025-012: Server-Side Request Forgery via Webhooks](https://news.typo3.com/security/advisory/typo3-core-sa-2025-012)
- [TYPO3-CORE-SA-2025-013: Unverified Password Change for Backend Users](https://news.typo3.com/security/advisory/typo3-core-sa-2025-013)
- [TYPO3 CMS Webhooks Server Side Request Forgery (GHSA-p4xx-m758-3hpx)](https://github.com/advisories/GHSA-p4xx-m758-3hpx)
- [Unverified Password Change for Backend Users (GHSA-3jrg-97f3-rqh9)](https://github.com/TYPO3/typo3/security/advisories/GHSA-3jrg-97f3-rqh9)
- [NVD - CVE-2025-47936 Detail](https://nvd.nist.gov/vuln/detail/cve-2025-47936)
- [NVD - CVE-2025-11183 Detail](https://nvd.nist.gov/vuln/detail/CVE-2025-11183)
- [CVE-2025-11183 Impact, Exploitability, and Mitigation Steps](https://www.wiz.io/vulnerability-database/cve/cve-2025-11183)
- [CVE-2025-47936: TYPO3 CMS Webhooks SSRF Flaw](https://www.miggo.io/vulnerability-database/cve/CVE-2025-47936)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2450
