TYPO3 Demo and QA Best Practices Join Forces
Demo Project
The TYPO3 demo site is available at demo.typo3.org. The goal of the project is to provide an instance where anyone is able…
This Is Lina Wolf, the New Documentation Team Co-Lead
“After completing my computer science studies in 2006, I got a boring Java job,” says Lina. “But then I met someone who showed me TYPO3…
TYPO3 11.5.12 and 10.4.30 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.12 LTS
- TYPO3 10.4.30 LTS
Further upgrade instructions
No database…
TYPO3-CORE-SA-2022-005: Insufficient Session Expiration in Admin Tool
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2022-004: Cross-Site Scripting in Frontend Login Mailer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-003: Cross-Site Scripting in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-002: Information Disclosure via Exception Handling/Logger
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2022-001: Information Disclosure via Export Module
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3 11.5.11 and 10.4.29 security releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.11 LTS
- TYPO3 10.4.29 LTS
All versions are security releases and contain…
TYPO3-EXT-SA-2022-013: Cross-Site Scripting in extension "AMEOS - TarteAuCitron (GDPR cookie banner and tracking management / French RGPD compatible)" (ameos_tarteaucitron)
It has been discovered that the extension "AMEOS - TarteAuCitron (GDPR cookie banner and tracking management / French RGPD compatible)"…
TYPO3-EXT-SA-2022-012: Cross-Site Scripting in extension "Embedding schema.org vocabulary" (schema)
It has been discovered that the extension "Embedding schema.org vocabulary" (schema) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2022-011: Cross-Site Scripting in extension "Matomo Integration" (matomo_integration)
It has been discovered that the extension "Matomo Integration" (matomo_integration) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2022-010: Cross-Site Scripting in extension "libconnect" (libconnect)
It has been discovered that the extension "libconnect" (libconnect) is susceptible to Cross-Site Scripting.
typo3.org Website Team Report 2022 Q1
Sprints / t3o Remote Days
We have done t3o Remote Days on:
- January 15th and 25th
- February 15th and 25th
- March 15th and 25th
We…
Deprecation and Shutdown of TER SOAP Interface
The SOAP interface was introduced more than 15 years ago, for managing and uploading extensions. TYPO3 version 4.5 was the last version…
GDPR Report 2021
Data protection measures affect 983 TYPO3 Association members, and the 12,894 registered users of typo3.org. Olivier Dobberkau, Alain…
Documenting TYPO3 Version 12
Extension Authors Need Good Docs Too
It’s not sure integrators and editors that rely on up-to-date documentation. Extension authors…
Standardization of TYPO3 Documentation—May 2022
To help foster distribution and contribution for your TYPO3 extension, Composer package, or standalone manual, apply the revised TYPO3 documentation…
Why TYPO3 Certifications Matter
TYPO3 certifications can help you validate your skills and advance your career. They will likely increase your chances of higher pay, better job…
TYPO3 11.5.10 and 10.4.28 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.10 LTS
- TYPO3 10.4.28 LTS
Both versions are maintenance releases only.
…
Announcement of Core Mergers 2022
In March 2022, we announced the call for Core Mergers. We welcome familiar faces and new contributors to the team to help to shape the…
Structured Content Initiative—What Happened Between November 2021 and April 2022?
The Structured Content Initiative is the core Strategic Initiative focused on improving the content editing user experience in TYPO3…
TYPO3-EXT-SA-2022-009: Cross-Site Scripting in extension "Grid Elements" (gridelements)
It has been discovered that the extension "Grid Elements" (gridelements) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2022-008: Multiple vulnerabilities in extension "Adminer" (t3adminer)
It has been discovered that the extension "Adminer" (t3adminer) is susceptible to Server-side request forgery and Cross-Site Scripting.
TYPO3-EXT-SA-2022-007: SQL Injection in extension "One is Enough Library" (oelib)
It has been discovered that the extension "One is Enough Library" (oelib) is susceptible to SQL Injection.
TYPO3-EXT-SA-2022-006: SQL Injection in extension "Seminar Manager" (seminars)
It has been discovered that the extension "Seminar Manager" (seminars) is susceptible to SQL Injection.
TYPO3-EXT-SA-2022-005: Remote Code Execution in extension "Job portal" (psvneo_jobfair)
- Release Date: April 26, 2022
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
Harbor Talk Videos
Did you happen to catch the TYPO3 Harbor Talks video series? TYPO3 Project Lead, Benni Mack joins Mathias Schreiber, CEO at TYPO3 GmbH, in the Media…
TYPO3 11.5.9 and 10.4.27 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 11.5.9 LTS
- TYPO3 10.4.27 LTS
Both versions are maintenance releases only.
…
Presentation: Candidates for the Board and Business Control Committee Elections
Thank you to everyone who has agreed to run for office!
For the Board
We have 6 candidates for 4 open positions: