TYPO3-PSA-2025-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
TYPO3-EXT-SA-2025-010: Insecure Direct Object Reference in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Insecure Direct Object Reference.
TYPO3-EXT-SA-2025-009: Insecure Direct Object Reference in extension "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
TYPO3-EXT-SA-2025-008: Multiple vulnerabilities in extension "Front End User Registration" (sr_feuser_register)
It has been discovered that the extension "Front End User Registration" (sr_feuser_register) is susceptible to Remote Code Execution and Insecure…
TYPO3-EXT-SA-2025-007: Multiple vulnerabilities in extension "Backup Plus" (ns_backup)
It has been discovered that the extension "Backup Plus" (ns_backup) is susceptible to Command Injection, Predictable Resource Location and Cross-Site…
TYPO3-EXT-SA-2025-006: Insecure Direct Object Reference in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Insecure Direct Object Reference.
TYPO3 13.1.1, 12.4.15 and 11.5.37 security releases published
The versions 13.1.1, 12.4.15 and 11.5.37 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2024-010: Uncontrolled Resource Consumption in ShowImageController
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-CORE-SA-2024-009: Cross-Site Scripting in ShowImageController
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2024-008: Cross-Site Scripting in Form Manager Module
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2024-007: HTML Injection in History Module
It has been discovered that TYPO3 CMS is vulnerable to HTML injection.
Call for Community Budget Ideas (Q3/2024)
The TYPO3 Association has officially launched the third community budget process of 2024.
The Comprehensive Guide to Enterprise CMS with TYPO3
The choice of an enterprise CMS should not be taken lightly. This guide should support your business in choosing the right enterprise CMS.
TYPO3 Surfcamp 2024
Young developers Lisa-Maria Schedlberger & Julia Gruber share their first-hand experience of fun-in-the-sun at TYPO3 Surfcamp.
T3CON24 & TYPO3 Awards: Tickets, Award Submissions & Event Details
Register now for T3CON24 and the TYPO3 Awards. Experience three days of innovative talks, networking, and celebrate the community's best at the TYPO3…
Results of Q1/2024 Community Budget Ideas
Significant progress for TYPO3: Rector rules, image rendering, simplified translation handling, and ACL improvements.
Community Budget Idea Report: Image Rendering Improvements
Marcin Sagol gives an in-depth report on the Q1 work undertaken to research solutions for asynchronous image rendering on the TYPO3 frontend. Take a…
Showcase Your Project: Explore Exciting New TYPO3 Award Categories and Deadline Updates
Be sure to mark your calendars for May 2nd and take note of the four new award categories introduced for this year's event!
TYPO3 v13.1—The Surfer’s Starterkit
Today we published the second sprint release of the v13 series: TYPO3 version 13.1. You can now consolidate site configurations as Site Sets and reuse…
Where To? Building the Road to EU Policy Compliance
5 February 2024, I attended a workshop in Brussels, Belgium, with representatives from many large open-source projects. With one person from each…
T3CON Recap—TYPO3 CMS & AI: Three Snapshots of AI-Powered Content Management
AI will change content management forever. At T3CON23, speakers demonstrated AI-powered CMS features far beyond text and image generation.
TYPO3 Rector on the Move
TYPO3 Rector has become an indispensable tool when upgrading TYPO3 instances from one major version to another. My colleagues and I joined the TYPO3…
Report From the EU Open Source Policy Summit
2023 showed us that it is important for TYPO3 to keep policy makers better informed. This event in Brussels, Belgium, was a source of new knowledge…
Reflections on SymfonyCon Brussels 2023
I had the opportunity to attend, and present at, SymfonyCon 2023 in Brussels. This was a fantastic event that brought together developers and…
TYPO3 12.4.14 maintenance release published
The version 12.4.14 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3 Camp Mitteldeutschland and a Newcomer’s Introduction to Open Source CMS
My first day as a TYPO3 GmbH employee, meeting the community and gaining valuable insights into the world of TYPO3 open source CMS.
T3CON Recap—AI Demystified: Sustainable and Intelligent Best Practices for Artificial Intelligence
Misconceptions, uncomfortable facts, and best practices. Thought leader, hosting expert, and AI engineer discuss potentials and challenges of AI.
Optimize Your TYPO3 Experience: Simplified ELTS Purchasing Through My TYPO3
In an effort to streamline the online purchase process, from now on, you will be completing any ELTS service purchasing through my.typo3.org.
TYPO3-EXT-SA-2024-002: Authentication Bypass in "OpenID Connect Authentication" (oidc)
It has been discovered that the extension "OpenID Connect Authentication" (oidc) is susceptible to Authentication Bypass.