Status Update: the TYPO3 Guidebook
Visit the TYPO3 Book website to find out how you can get in touch.
We’ve Booked Our Publisher: Apress!
Apress is a great fit for the first book about…
Advice: No Physical TYPO3 Association Meetings Until Further Notice
Advice Currently in Effect. This page will be kept up-to-date with the current status of the Board’s advice. Feel free to return here to see the…
Structured Content Initiative - What Happened in February?
The Structured Content Initiative is the core Strategic Initiative focused on improving the content editing user experience in TYPO3 CMS. Read our…
TYPO3-EXT-SA-2020-003: Multiple vulnerabilities in extension "Magalone Flipbook for TYPO3" (magaloneflipbook)
- Release Date: March 10, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Vulnerability…
TYPO3-EXT-SA-2020-002: Remote Code Execution in extension "PHPUnit" (phpunit)
- Release Date: March 10, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Vulnerability…
TYPO3-EXT-SA-2020-001: SQL Injection in extension "phpmyadmin" (phpmyadmin)
- Release Date: March 10, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Vulnerability…
This Month in TYPO3 - February 2020 - Issue #14
This issue is dedicated to the upcoming TYPO3 v10 LTS. We're now in the feature freeze phase and this time will be used to polish everything smooth…
Report: Google CMS Security Summit 2020 in Munich
This year, the event took place in Munich, Germany, and Oliver Hader, Benni Mack, and Torben Hansen from the Security Team represented TYPO3.
After a…
We Want You as Core Merger in 2020
In March 2019, we introduced a revised core development structure, consisting of four groups for coordinating TYPO3 Core development
- Core…
TYPO3 Version 10.3 — Almost There
Yes, we are getting closer to the TYPO3 v10 LTS release with every day and with every code commit — and you can feel it. Today we are super excited to…
10 Ways to Get Ready for TYPO3 v10
Get in it to win it! There are TWO ways to be entered in a prize draw to help boost TYPO3 adoption. Update your TYPO3 Extension or write about TYPO3.…
TYPO3 9.5.14 and 8.7.31 maintenance releases published
We are announcing the release of the following TYPO3 updates:
- TYPO3 9.5.14 LTS
- TYPO3 8.7.31 LTS
All versions are maintenance releases and contain…
An Update About the Dashboard for TYPO3
This blog post was originally posted on richardhaeser.com. It is published at typo3.org with permission from the author.
Current situation
In…
News from the Structured Content Initiative
TYPO3 core development is organised into Strategic Initiatives where people with common interests and skills can improve a specific area of TYPO3…
Report from the Board QSA, November 2019
The TYPO3 Association Board met at the new TYPO3 Company office in Düsseldorf, Germany, 4th to 5th November 2019.
As it coincided with a regular open…
Expanding TYPO3 with Your Help this Spring
If you’re reading this article, you’re likely already a member of the TYPO3 community. You have no doubts that we’re working with the best, most…
Land ho! Feature Freeze Ahead!
TYPO3 v10.2 in December 2019 marked the last release before the Feature Freeze release in February 2020. Now is the time for TYPO3 extension…
The TYPO3 Marketing Team's 2020 Vision
Create. Communicate. Contribute.
Under our newly developed slogan, we as the 'newly formed' Marketing Team are looking forward to kick-start the new…
TYPO3 Developers—Get Certified!
The TYPO3 Association launched the official TYPO3 certification program more than a decade ago. Today, we offer four certification streams and one of…
21 April 2020: TYPO3 v10 LTS Release and Party
The General Assembly is only the second reason why the date has been moved. The primary reason is that the original date (7 April 2020, two weeks…
TYPO3-EXT-SA-2019-023: CSRF in extension "femanager" (femanager)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-022: Privilege Escalation in extension "femanager direct mail subscription" (femanager_dmail_subscribe)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-021: Cross Site Scripting in extension "File List" (file_list)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-020: CSRF in extension "Change password for frontend users" (fe_change_pwd)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-EXT-SA-2019-019: Multiple vulnerabilities in extension "MKSamlAuth" (mksamlauth)
- Release Date: December 17, 2019
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3 10.2.2, 9.5.13 and 8.7.30 security releases published
The TYPO3 Community announces the versions 10.2.2, 9.5.13 LTS and 8.7.30 LTS of the TYPO3 Enterprise Content Management System.
TYPO3-CORE-SA-2019-026: Insecure Deserialization in Query Generator & Query View
- Component Type: TYPO3 CMS
- Subcomponent: Query Generator & Query View (ext:lowlevel, ext:core)
- Release Date: December 17, 2019
- Vulnerability Type:…
TYPO3-CORE-SA-2019-025: SQL Injection in low-level Query Generator
- Component Type: TYPO3 CMS
- Subcomponent: Query Generator (ext:lowlevel)
- Release Date: December 17, 2019
- Vulnerability Type: SQL Injection
- …
TYPO3-CORE-SA-2019-024: Directory Traversal on ZIP extraction
- Component Type: TYPO3 CMS
- Subcomponent: Extension Manager (ext:extensionmanger)
- Release Date: December 17, 2019
- Vulnerability Type: Directory…
TYPO3-CORE-SA-2019-023: Cross-Site Scripting in Filelist Module
- Component Type: TYPO3 CMS
- Subcomponent: Filelist Module (ext:filelist)
- Release Date: December 17, 2019
- Vulnerability Type: Cross-Site Scripting
- …