TYPO3-EXT-SA-2019-023: CSRF in extension "femanager" (femanager)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-022: Privilege Escalation in extension "femanager direct mail subscription" (femanager_dmail_subscribe)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-021: Cross Site Scripting in extension "File List" (file_list)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-020: CSRF in extension "Change password for frontend users" (fe_change_pwd)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-019: Multiple vulnerabilities in extension "MKSamlAuth" (mksamlauth)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3 10.2.2, 9.5.13 and 8.7.30 security releases published
The TYPO3 Community announces the versions 10.2.2, 9.5.13 LTS and 8.7.30 LTS of the TYPO3 Enterprise Content Management System.
TYPO3-CORE-SA-2019-026: Insecure Deserialization in Query Generator & Query View
- Component Type: TYPO3 CMS
- Subcomponent: Query Generator & Query View (ext:lowlevel, ext:core)
- Release Date: December 17, 2019
- Vulnerability Type:…
TYPO3-CORE-SA-2019-025: SQL Injection in low-level Query Generator
- Component Type: TYPO3 CMS
- Subcomponent: Query Generator (ext:lowlevel)
- Release Date: December 17, 2019
- Vulnerability Type: SQL Injection
- …
TYPO3-CORE-SA-2019-024: Directory Traversal on ZIP extraction
- Component Type: TYPO3 CMS
- Subcomponent: Extension Manager (ext:extensionmanger)
- Release Date: December 17, 2019
- Vulnerability Type: Directory…
TYPO3-CORE-SA-2019-023: Cross-Site Scripting in Filelist Module
- Component Type: TYPO3 CMS
- Subcomponent: Filelist Module (ext:filelist)
- Release Date: December 17, 2019
- Vulnerability Type: Cross-Site Scripting
- …
TYPO3-CORE-SA-2019-022: Cross-Site Scripting in Link Handling
- Component Type: TYPO3 CMS
- Subcomponent: Link Handling (ext:core, ext:frontend)
- Release Date: December 17, 2019
- Vulnerability Type: Cross-Site…
TYPO3-CORE-SA-2019-021: Cross-Site Scripting in Form Framework validation handling
- Component Type: TYPO3 CMS
- Subcomponent: Form Framework (ext:form)
- Release Date: December 17, 2019
- Vulnerability Type: Cross-Site Scripting
- …
TYPO3-PSA-2019-011: Possible Insecure Deserialization in Extbase Request Handling
- Component Type: TYPO3 CMS
- Subcomponent: Extbase Request Handling (ext:extbase)
- Release Date: December 17, 2019
- Impact: Possible Insecure…
TYPO3-PSA-2019-010: Cross-Site Scripting Vulnerabilities in File Upload Handling
It has been discovered that TYPO3 is susceptible to cross-site scripting.
Announcing Selected Budget Ideas for 2020
The TYPO3 Association Budget Committee made a strategic selection of 9 topics to pursue from a pool of 13 submitted budget ideas.
The committee…
Upcoming Elections in the TYPO3 Association 2020
As the Expert Advisory Board will be disbanded and replaced by the Board, all eight positions in the Board will be elected by the members of the TYPO3…
TYPO3 Version 10.2 — Treasure Hunting!
TYPO3 v10.2 is out now — the last sprint release of the year. A lot of functionality was developed during the TYPO3 Initiative Week (T3INIT19) and…
Skill Verification Access for the TYPO3 Academic Committee
Sign Up for a Free Educational SkillDisplay Membership
The TYPO3 Academic Committee is the interface between universities and the TYPO3 community. To…
TYPO3 Initiative Week—Insider Report
24 participants from 8 initiatives met for 1 week in Festenburg, Oberharz, Germany to communicate, collaborate and connect with each other and bring…
TYPO3 Conference Wrap Up!
The 14th TYPO3 Conference is a wrap! This is the main event for the business community in the TYPO3 ecosystem. Sharing knowledge around building your…
Impressions of the Developer Days from the Documentation Team
Find out more about the event:
Impressions from T3DD with quotes from more speakers and attendees.
What’s Up, Docs?
TYPO3 Developer Days is a great…
Impressions from T3DD19
Find out more
When possible, speakers have posted links to their slides in their talk descriptions in the program. The Documentation Team also got…
TYPO3 9.5.11 and 8.7.29 maintenance releases published
The TYPO3 Community announces the versions 9.5.11 LTS and 8.7.29 LTS of the TYPO3 Enterprise Content Management System.
TYPO3-PSA-2019-009: Truncated passwords during authentication process on typo3.org services
- Release Date: October 30, 2019
- Component Type: LDAP passwort storage & authentication (via my.typo3.org)
- Impact: Truncated password during…