TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework
It has been discovered that TYPO3 CMS is vulnerable to arbitrary code execution.
TYPO3-CORE-SA-2022-014: Insufficient Session Expiration after Password Reset
It has been discovered that TYPO3 CMS is susceptible to insufficient session expiration.
TYPO3-CORE-SA-2022-013: Weak Authentication in Frontend Login
It has been discovered that TYPO3 CMS is susceptible to weak authentication.
TYPO3-CORE-SA-2022-012: Denial of Service in Page Error Handling
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3 v12.1—Together As One
We are happy to announce the release of TYPO3 version 12.1, which comes with “Reactions”. This new feature enables TYPO3 to react to incoming…
Being TYPO3 at SymfonyCon Disneyland, Paris
Notes from a visit to Symfony Conference, Paris in November 2022.
Leadership Changes at TYPO3 GmbH
Daniel Fau has been the new interim CEO of TYPO3 GmbH since December 1, 2022. • Mathias Schreiber is leaving the company. • The search for a…
Status Report on Sustainability and the Buzzword Bingo From Boye 22
Notes from the CMS Experts track of the Boye 22 digital leadership conference in Aarhus, Denmark, 9 November 2022.
Focus Code Sprint Rosenheim Recap
The development of TYPO3 CMS is mainly done by volunteers in their free time. This often means that coordinating and focussing on bigger topics can be…
TYPO3 11.5.19 maintenance release published
The version 11.5.19 of the TYPO3 Enterprise Content Management System has just been released.
Through the Looking Glass (or Being TYPO3 at DrupalCon)
Notes from a visit to DrupalCon Europe, in Prague, September 2022.
TYPO3 11.5.18 maintenance release published
The version 11.5.18 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3-EXT-SA-2022-015: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
UX and TYPO3—the Challenges for the Next Five Years
During the T3DD22, Annett Jähnichen and Rachel Foucard presented the TYPO3 UX Team and its work. With this article we would like to give you an…
Teaming Up For Better Extensions
Previously, the TYPO3 group for QA Best Practices was a loose group financed via budgets every year. We recently asked the TYPO3 Association to become…
TYPO3 11.5.17 maintenance release published
The version 11.5.17 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3 Education Committee: TCCE Certification Team Final Update
Since the Kick-Off-Phase, the TCCE Certification Team has been working on updating the skills for TYPO3 version 11. This is now officially complete.
TYPO3 v12.0—Release Your Power
TYPO3 version 12.0 is out! This is the first of five releases we plan to make over the next six months on the way to the long-term support release in…
Server Team Status Report
Like any internal IT department, inquiries come across our desk day in and day out. Most often, we’re helping end-users and community members when…
Get Ready for TYPO3 v12
The first sprint release of the TYPO3 v12 series is just around the corner. We plan to release TYPO3 version 12.0 in less than two weeks, on 4 October…
TYPO3 11.5.16 and 10.4.32 security releases published
The versions 11.5.16 and 10.4.32 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2022-011: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-010: Cross-Site Scripting in <f:asset.css> view helper
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-009: Stored Cross-Site Scripting via FileDumpController
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-008: Missing check for expiration time of password reset token for backend users
It has been discovered that TYPO3 CMS is vulnerable to broken access control.
TYPO3-CORE-SA-2022-007: User Enumeration via Response Timing
It has been discovered that TYPO3 CMS is vulnerable to information disclosure.
TYPO3-CORE-SA-2022-006: Denial of Service in Page Error Handling
It has been discovered that TYPO3 CMS is susceptible to denial of service.
Introducing a New Way to Meet TYPO3
There is a new event listing at typo3.org, where all of the titles start with “Meet TYPO3 at …”. These are external events where a person representing…
Documentation Team—Summer Update 2022
It’s been a busy summer in the northern hemisphere and we’ve got plenty of updates to share.