Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-56096: CWE-943 Improper Neutralization of Special Elements in Data Query Logic in TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"CVE-2026-56096
0

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration.

Join the discussion
CVE-2026-56095: CWE-502 Deserialization of Untrusted Data in TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"CVE-2026-56095
0

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If user-generated content saved in the TYPO3 database can reach an indexed field, this exposes a PHP Object Injection surface.

Join the discussion
CVE-2026-56094: CWE-943 Improper Neutralization of Special Elements in Data Query Logic in TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"CVE-2026-56094
0

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read public documents belonging to another site. The same root cause also affects the suggest top-results path when suggest is enabled.

Join the discussion
CVE-2026-56093: CWE-639 Authorization Bypass Through User-Controlled Key in TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"CVE-2026-56093
0

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

Join the discussion
CVE-2026-56092: CWE-862 Missing Authorization in TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"CVE-2026-56092
0

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:composer/apache-solr-for-typo3/solr
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses