A vulnerability marked as problematic has been reported in TYPO3 up to 13.4.33/14.3.5. The impacted element is an unknown function of the component Referrer Enforcement. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-19418. The attack can be initiated remotely. There is not any exploit available.