TYPO3 10.4.56 and 11.5.50 ELTS Released
Still sticking to an older version of TYPO3? Today, 10.4.56 and 11.5.50 have been released. Staying on top of maintenance updates should be a top…
TYPO3 13.4.24 and 12.4.42 maintenance releases published
The versions 13.4.24 and 12.4.42 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-EXT-SA-2026-001: Insecure Deserialization in extension "Mailqueue" (mailqueue)
It has been discovered that the extension "Mailqueue" (mailqueue) is vulnerable to insecure deserialization.
TYPO3-EXT-SA-2026-001: Insecure Deserialization in extension "Mailqueue" (mailqueue)
It has been discovered that the extension "Mailqueue" (mailqueue) is vulnerable to insecure deserialization.
AI Integration in TYPO3 Via MCP: The End of Backend Fumbling
Content management meets artificial intelligence — and takes a quantum leap. With the Model Context Protocol (MCP) extension for TYPO3, editors…
TYPO3 14.0.2, 13.4.23 and 12.4.41 security releases published
The versions 14.0.2, 13.4.23 and 12.4.41 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 10.4.55 and 11.5.49 ELTS Released
Still sticking to an older version of TYPO3? Today, 10.4.55 and 11.5.49 have been released. Staying on top of maintenance updates should be a top…
TYPO3-CORE-SA-2026-004: Insecure Deserialization via Mailer File Spool
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2026-004: Insecure Deserialization via Mailer File Spool
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2026-003: Broken Access Control in Recycler Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-003: Broken Access Control in Recycler Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-002: Broken Access Control in Redirects Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-001: Broken Access Control in Edit Document Controller
It has been discovered that TYPO3 CMS is susceptible to broken access control.
Recognizing Open-Source Work as Volunteering in Germany
TYPO3 Association Board member Boris Hinzer outlines a new petition advocating for legal recognition of open-source work as volunteer service.
Coder's Corner: December 2025
See the full recap of TYPO3’s November core contributions with 47 contributors, 148 reviews, bug fixes, features, and a big thank-you to our…
Vote Now! Budget Ideas for Round 1/2026 Have Been Published
The call for community budget ideas for the first round of 2026 was successful: Six community and three team ideas have made it to the poll. These…
This Month in TYPO3: December 2025
December closed out 2025 with solid releases and active community work. From security updates and tooling progress to conference highlights and…
TYPO3-EXT-SA-2025-016: Vulnerability in bundled package in extension "Single Sign-on with SAML" (md_saml)
It has been discovered that the extension "Single Sign-on with SAML" (md_saml) bundles a vulnerable version of “onelogin/php-saml“ which is…
TYPO3-EXT-SA-2025-015: Broken Authentication in extension "Modules" (modules)
It has been discovered that the extension "Modules" (modules) is susceptible to Broken Authentication.
TYPO3-EXT-SA-2025-014: Vulnerability in bundled package in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) bundles a vulnerable version of "phpoffice/phpspreadsheet", which is…
TYPO3-EXT-SA-2025-013: Vulnerability in bundled package in extension "Base Excel" (base_excel)
It has been discovered that the extension "Base Excel" (base_excel) bundles a vulnerable version of “phpoffice/phpspreadsheet“ which is susceptible to…
TYPO3-EXT-SA-2025-012: Cross-Site Scripting in extension "Form to Database" (form_to_database)
It has been discovered that the extension "Form to Database" (form_to_database) is susceptible to Cross-Site Scripting.
TYPO3-CORE-SA-2025-023: Information Disclosure via CSV Download
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-022: Information Disclosure in Workspaces Module
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-021: Broken Access Control in Backend AJAX Routes
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2025-020: Information Disclosure via File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-019: Insufficient Entropy in Password Generation
It has been discovered that TYPO3 CMS is susceptible to insufficient entropy.
TYPO3-CORE-SA-2025-018: Denial of Service in TYPO3 Bookmark Toolbar
It has been discovered that TYPO3 CMS is susceptible to denial of service.
TYPO3-CORE-SA-2025-017: Open Redirect in TYPO3 CMS
It has been discovered that TYPO3 CMS is susceptible to open redirect.
TYPO3-EXT-SA-2025-011: Command Injection in extension "TYPO3 Backup Plus" (ns_backup)
It has been discovered that the extension "TYPO3 Backup Plus" (ns_backup) is susceptible to Command Injection.