TYPO3 10.4.55 and 11.5.49 ELTS Released
Still sticking to an older version of TYPO3? Today, 10.4.55 and 11.5.49 have been released. Staying on top of maintenance updates should be a top…
Insecure Deserialization via Mailer File Spool
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
Broken Access Control in Recycler Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
Broken Access Control in Redirects Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
Broken Access Control in Edit Document Controller
It has been discovered that TYPO3 CMS is susceptible to broken access control.
Recognizing Open-Source Work as Volunteering in Germany
TYPO3 Association Board member Boris Hinzer outlines a new petition advocating for legal recognition of open-source work as volunteer service.
Coder's Corner: December 2025
See the full recap of TYPO3’s November core contributions with 47 contributors, 148 reviews, bug fixes, features, and a big thank-you to our…
Vote Now! Budget Ideas for Round 1/2026 Have Been Published
The call for community budget ideas for the first round of 2026 was successful: Six community and three team ideas have made it to the poll. These…
This Month in TYPO3: December 2025
December closed out 2025 with solid releases and active community work. From security updates and tooling progress to conference highlights and…
Digital Accessibility: Why Companies Need to Act Now
Digital accessibility is becoming mandatory under the BFSG. Learn why accessibility is more than a technical task and how companies can implement it…
Community Budget Report: Rector and Fractor Updates for TYPO3 v14
Simon Schaufelberger provides an update on his Community Budget Idea to create the remaining Rector rules for TYPO3 v14 and to add new features for…
Preparing for TYPO3 v14 LTS: Consultant Certification Task Force Advances into 2026
The TYPO3 CMS Certified Consultant Task Force wrapped up 2025 with an intensive sprint in Hannover, laying the groundwork for the upcoming TYPO3 v14…
2025 TYPO3 Retrospective
Discover TYPO3’s biggest milestones of 2025—from the TYPO3.com relaunch to global events, new partnerships, v14.0, and a look ahead at what’s coming…
Enhanced Email Configuration — Approach and First Version
Email may be old, but it remains critical when reliability matters — and TYPO3 still lacks awareness of modern deliverability standards. This article…
TYPO3-EXT-SA-2025-016: Vulnerability in bundled package in extension "Single Sign-on with SAML" (md_saml)
It has been discovered that the extension "Single Sign-on with SAML" (md_saml) bundles a vulnerable version of “onelogin/php-saml“ which is…
Best Practices Team On-Site Sprint
Are you interested in learning more about best practices for developing high-quality TYPO3 extensions? Or do you have some new ideas that should be…
TYPO3-EXT-SA-2025-015: Broken Authentication in extension "Modules" (modules)
It has been discovered that the extension "Modules" (modules) is susceptible to Broken Authentication.
TYPO3-EXT-SA-2025-014: Vulnerability in bundled package in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) bundles a vulnerable version of "phpoffice/phpspreadsheet", which is…
TYPO3-EXT-SA-2025-013: Vulnerability in bundled package in extension "Base Excel" (base_excel)
It has been discovered that the extension "Base Excel" (base_excel) bundles a vulnerable version of “phpoffice/phpspreadsheet“ which is susceptible to…
TYPO3-EXT-SA-2025-012: Cross-Site Scripting in extension "Form to Database" (form_to_database)
It has been discovered that the extension "Form to Database" (form_to_database) is susceptible to Cross-Site Scripting.
TYPO3-CORE-SA-2025-023: Information Disclosure via CSV Download
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-022: Information Disclosure in Workspaces Module
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-021: Broken Access Control in Backend AJAX Routes
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2025-020: Information Disclosure via File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to information disclosure.