Standardization of TYPO3 Documentation—May 2022
To help foster distribution and contribution for your TYPO3 extension, Composer package, or standalone manual, apply the revised TYPO3 documentation…
Why TYPO3 Certifications Matter
TYPO3 certifications can help you validate your skills and advance your career. They will likely increase your chances of higher pay, better job…
TYPO3 11.5.10 and 10.4.28 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.10 LTS
- TYPO3 10.4.28 LTS
Both versions are maintenance releases only.
…
Announcement of Core Mergers 2022
In March 2022, we announced the call for Core Mergers. We welcome familiar faces and new contributors to the team to help to shape the…
Structured Content Initiative—What Happened Between November 2021 and April 2022?
The Structured Content Initiative is the core Strategic Initiative focused on improving the content editing user experience in TYPO3…
TYPO3-EXT-SA-2022-009: Cross-Site Scripting in extension "Grid Elements" (gridelements)
It has been discovered that the extension "Grid Elements" (gridelements) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2022-008: Multiple vulnerabilities in extension "Adminer" (t3adminer)
It has been discovered that the extension "Adminer" (t3adminer) is susceptible to Server-side request forgery and Cross-Site Scripting.
TYPO3-EXT-SA-2022-007: SQL Injection in extension "One is Enough Library" (oelib)
It has been discovered that the extension "One is Enough Library" (oelib) is susceptible to SQL Injection.
TYPO3-EXT-SA-2022-006: SQL Injection in extension "Seminar Manager" (seminars)
It has been discovered that the extension "Seminar Manager" (seminars) is susceptible to SQL Injection.
TYPO3-EXT-SA-2022-005: Remote Code Execution in extension "Job portal" (psvneo_jobfair)
- Release Date: April 26, 2022
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
Harbor Talk Videos
Did you happen to catch the TYPO3 Harbor Talks video series? TYPO3 Project Lead, Benni Mack joins Mathias Schreiber, CEO at TYPO3 GmbH, in the Media…
TYPO3 11.5.9 and 10.4.27 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.9 LTS
- TYPO3 10.4.27 LTS
Both versions are maintenance releases only.
…
Presentation: Candidates for the Board and Business Control Committee Elections
Thank you to everyone who has agreed to run for office!
For the Board
We have 6 candidates for 4 open positions:
Open Discussion on the TYPO3 Association Budget Ideas for 2022
Here is a quick overview of the 2022 budget pools: The budget for 2022 is estimated at €200,000. Please be aware this amount doesn’t…
The FGTCLB Joins TYPO3 Platinum Membership
Knowledge exchange and community involvement are the motivation for one of the world’s largest TYPO3 agency networks joining the top-tier TYPO3…
Code the TYPO3 Core in 2022
In March 2019, we introduced a revised core development structure, consisting of four groups for coordinating TYPO3 Core development:
- …
Now in Effect: the New Code of Conduct
The Code of Conduct now applies to all persons present at or in the following:
- Official TYPO3 events
- Official TYPO3 community events…
TYPO3 11.5.8 and 10.4.26 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.8 LTS
- TYPO3 10.4.26 LTS
Both versions are maintenance releases only.
…
TYPO3 11.5.7 and 10.4.25 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.7 LTS
- TYPO3 10.4.25 LTS
Both versions are maintenance releases only.…
TYPO3-PSA-2022-001: Sanitization bypass in SVG Sanitizer
- Component Type: TYPO3 CMS
- Subcomponent: SVG Sanitizer (based on enshrined/svg-sanitize)
- Release Date: February 22nd, 2022
- Impact:…
We Need You for the Board and the Business Control Committee!
Positions are available for the Board and the Business Control Committee (BCC), and you can nominate yourself for one of these…
TYPO3-EXT-SA-2022-004: File Content Injection in extension "Hardcoded text to Locallang" (mqk_locallangtools)
- Release Date: February 15, 2022
- Component Type: Third party extension. This extension is not a part of the TYPO3 default…
TYPO3-EXT-SA-2022-003: Insecure direct object reference in extension "Varnishcache" (varnishcache)
- Release Date: February 15, 2022
- Component Type: Third party extension. This extension is not a part of the TYPO3 default…
TYPO3-EXT-SA-2022-002: Cross-Site Scripting in extension "Bookdatabase" (extbookdatabase)
- Release Date: February 15, 2022
- Component Type: Third party extension. This extension is not a part of the TYPO3 default…
TYPO3-EXT-SA-2022-001: Server-side request forgery in extension "Kitodo.Presentation" (dlf)
- Release Date: February 15, 2022
- Component Type: Third party extension. This extension is not a part of the TYPO3 default…
New Code of Conduct: Cast Your Vote
Back in September 2021, the Ombudsperson Group started an extensive review process for a new Code of Conduct for the…
TYPO3 and its Accessibility in the Backend
What Does Digital Accessibility Mean?
It is a task for society as a whole to provide everyone with equal access to relevant information…
Team Report 2021—typo3.org Website Team
General
We prepared our budget for 2021 for working completely remote, and envisioned some ambitious projects for our websites and…
TYPO3 11.5.6 and 10.4.24 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.6 LTS
- TYPO3 10.4.24 LTS
Both versions are maintenance releases only.
…
Call for Budget Application Ideas—Association Budget 2022
In an earlier article, the Board introduced the new budget process for the Association budget for 2022. With the Business Control…