TYPO3-EXT-SA-2021-004: Cross-Site Scripting in extension "2 Clicks for External Media" (media2click)
- Release Date: April 27, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
Documentation Team Sweeping Week
At the start of 2021, the TYPO3 Documentation Team initiated the concept of a "Sweeping Week". This is based on the idea of Kehrwoche…
Meet Volker Graubaum (Part 2), Chief Product Officer, TYPO3, Germany (Application Podcast S1E12)
In our last episode, Volker and I talked about how he sees TYPO3 CMS, the TYPO3 Association, and the community’s company, TYPO3 GmbH,…
New Policy for Committees and Official Teams
The TYPO3 Association’s Policy for Committees and Official Teams outlines the structure for teams, committees, and initiatives so that members can…
Meet Volker Graubaum (part 1 of 3!), Chief Product Officer of TYPO3, Germany (Application Podcast S1E11)
We ended up talking a long time … This is part 1 of 3 episodes featuring Volker!
Listen to the full interview in the audio player here,…
Introducing Free Skill Tracking and Verification for TYPO3 Association Members
Silver, Gold, and Platinum members of the TYPO3 Association now receive credits and a free business account at SkillDisplay.eu to manage, track and…
TYPO3 10.4.15 maintenance release published
The following TYPO3 update has been released:
- TYPO3 10.4.15 LTS
This version is a maintenance release only.
Further upgrade…
Results of the 2021 TYPO3 Association Elections
When the election closed, 4 April, more than 200 members had cast their votes.
Thank you to those candidates who participated, but who…
TYPO3 Trademark Registered in India and Ukraine
To make sure that we have enough rights to do so, we also register our trademark worldwide. Last year we registered our trademark in…
TYPO3 Mentorship Program 2021
With your involvement in 2021, it will be possible to conduct further programs that will help TYPO3 agencies to attract talent, and to…
Documentation Screenshots—Puppeteer Makes Life Easy
The Background
The initial idea was quite simple: Let someone manually update all screenshots in the official documentation.…
Meet Sybille Peters, Germany (Application Podcast S1E10)
Listen to the full interview in the audio player here, watch the interview video below, where you’ll also find a full transcript of our…
The TYPO3 Comparison Cards are Here!
They’ve been long in the making, and we’re excited to announce that the first batch is done and published!
TYPO3 Wiki (2004–2021)—Long Live the Documentation
During the last few years, a recurring topic has been the content of wiki.typo3.org—mainly because it was less and less used and…
Meet Andri Steiner, TYPO3 Server Team Lead, Switzerland (Application Podcast S1E9)
Listen to the full interview in the audio player here, watch the interview video below, where you’ll also find a full transcript of our…
TYPO3 General Assembly 2021
Register for the next TYPO3 General Assembly
Some readers may not be aware of how the TYPO3 project works, so this article is an…
Hand in Hand for Secure Websites—Making the Internet Safer
The TYPO3 Association is a member of eco—Association of the Internet Industry. The author is head of member services & head of cyber…
Meet Mathias Schreiber, TYPO3 GmbH CEO, Germany (Application Podcast S1E8)
Listen to the full interview in the audio player here, watch the interview video below, where you’ll also find a full transcript of our…
TYPO3 9.5.26 maintenance release published
The following TYPO3 update has been released:
- TYPO3 9.5.26 LTS
This version is a maintenance release only, and fixes a minor…
TYPO3-CORE-SA-2021-008: Cross-Site Scripting in Content Preview
- Component Type: TYPO3 CMS
- Subcomponent: Content Preview Renderer (ext:backend)
- Release Date: March 16, 2021
- Vulnerability Type:…
TYPO3-CORE-SA-2021-007: Cross-Site Scripting in Content Preview
- Component Type: TYPO3 CMS
- Subcomponent: Content Preview Renderer (ext:backend)
- Release Date: March 16, 2021
- Vulnerability Type:…
TYPO3-CORE-SA-2021-006: Cleartext storage of session identifier
- Component Type: TYPO3 CMS
- Subcomponent: Session Storage (ext:core)
- Release Date: March 16, 2021
- Vulnerability Type: Sensitive Data…
TYPO3-CORE-SA-2021-005: Denial of Service in Page Error Handling
- Component Type: TYPO3 CMS
- Subcomponent: Page Error Handling (ext:core, ext:frontend)
- Release Date: March 16, 2021
- Vulnerability…
TYPO3-CORE-SA-2021-004: Cross-Site Scripting in Form Framework
- Component Type: TYPO3 CMS
- Subcomponent: Form Framework (ext:form)
- Release Date: March 16, 2021
- Vulnerability Type: Cross-Site…
TYPO3-CORE-SA-2021-003: Broken Access Control in Form Framework
- Component Type: TYPO3 CMS
- Subcomponent: Form Framework (ext:form)
- Release Date: March 16, 2021
- Vulnerability Type: Broken Access…
TYPO3-CORE-SA-2021-002: Unrestricted File Upload in Form Framework
- Component Type: TYPO3 CMS
- Subcomponent: Form Framework (ext:form)
- Release Date: March 16, 2021
- Vulnerability Type: Unrestricted…
TYPO3 11.1.1, 10.4.14, 9.5.25 security releases published
The following TYPO3 updates have been released:
- TYPO3 11.1.1
- TYPO3 10.4.14 LTS
- TYPO3 9.5.25 LTS
- TYPO3 8.7.40 ELTS
- TYPO3 7.6.51…
TYPO3-CORE-SA-2021-001: Open Redirection in Login Handling
- Component Type: TYPO3 CMS
- Subcomponent: Login Handling (ext:core)
- Release Date: March 16, 2021
- Vulnerability Type: Open…
TYPO3-EXT-SA-2021-003: Cross-Site Scripting in extension "Aimeos shop and e-commerce framework" (aimeos)
- Release Date: Mar 16, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2021-002: Denial of Service in extension "Code Highlight" (codehighlight)
- Release Date: March 16, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …