TYPO3 CMS vulnerability scanner. Detects versions, enumerates extensions, and matches CVEs.
$ typo3-scan https://target.example.com
uv tool install git+https://github.com/evait-security/typo3-scan
Or for local development:
git clone https://github.com/evait-security/typo3-scan
cd typo3-scan
uv run typo3-scan https://target.example.com
For development with live source changes:
PYTHONPATH=. uv run --with httpx --with beautifulsoup4 --with rich --with packaging python3 -m typo3_scan <target>
typo3-scan [options] <target>
Arguments:
target Target URL (e.g. https://example.com)
Options:
-V, --version Show version
--timeout N HTTP timeout in seconds (default: 15)
--no-verify Disable TLS verification
--json JSON output
--no-color Disable color output
Version detection uses multiple techniques:
| Method | Description |
|---|---|
| Library fingerprinting | jQuery, RequireJS, flatpickr versions mapped to TYPO3 releases |
| Architecture detection | RequireJS = v11-, ES modules = v12+ |
| Asset hash analysis | Git commit hash in bust= parameters |
| Bootstrap/FA versions | Bootstrap major + FontAwesome version narrowing |
| Timestamp analysis | Asset timestamps correlated with release dates |
| Backend DOM analysis | Login page HTML structure, JS module registry |
Extension enumeration:
- Known extension path probing (CHANGELOG, ext_emconf.php, composer.json)
- Backend JS module analysis for non-system extensions
- System extension detection via sysext/ directory
CVE matching:
- 90+ core CVEs from 2019-2024 with version range expressions
- 15+ extension-specific CVEs
- Matches both exact and ranged versions
typo3_scan/
cli.py CLI with rich output
scanner.py Core orchestration
detect/
version.py Multi-technique version detection
fingerprint.py Library-to-version mapping database
plugins/
enumerate.py Extension enumeration
vulns/
cve.py CVE database and matching engine
utils/
http.py HTTP session and regex patterns