TYPO3-CORE-SA-2021-015: HTTP Host Header Injection in Request Handling
- Component Type: TYPO3 CMS
- Subcomponent: Request Handling (ext:core)
- Release Date: October 5, 2021
- Vulnerability Type: HTTP Header…
TYPO3 v11 LTS—Warp Speed
TYPO3 v11 LTS is out! Many enhancements, new features, and modern technologies under the hood make this version our best TYPO3 release yet. We have…
TYPO3-CORE-SA-2021-014: Cross-Site-Request-Forgery in Backend URI Handling
- Component Type: TYPO3 CMS
- Subcomponent: Backend URI Handling (ext:backend)
- Release Date: October 5, 2021
- Vulnerability Type:…
ELTS 9.5 Is Live—Extended Support for TYPO3 CMS Version 9
Support runtimes have a significant effect on the investment, especially for web applications. Sustainability plays an important role…
Meet Larry Garfield, TYPO3 Core Developer, Chicago (Application Podcast S02E07)
Shameless plug: Use this discount code to get your copy of Larry’s book, “Thinking Functionally in PHP.”
Listen to the full interview…
Documentation Restructuring—September Update
In our last update we announced that the first stage of the documentation restructure was complete. This work included an overhaul of…
TYPO3 v9 End of Free Support Announcement
In accordance with the TYPO3 lifecycle and deprecation policy, we announce that TYPO3 v9 LTS reaches its end of free support on 30 September 2021.…
TYPO3 Entry-Level Certification (Status Update September 2021)
The project is on track, aiming to launch in the first quarter of 2022.
What is the Aim of the Project?
We would like to get closer to…
TYPO3 10.4.21 and 9.5.31 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 10.4.21 LTS
- TYPO3 9.5.31 LTS
Both versions are maintenance releases only.
…
See What's On: TYPO3 University Days 2021
We have put together a colorful digital program for our online meeting and have attracted some great speakers: We will be talking about
…New Code of Conduct—Give Your Feedback!
The proposal we are presenting for your feedback has gone through an extensive review process within the Ombudsperson Group. Every word…
Meet Stefan Busemann, Multi-talented TYPO3 Contributor, Germany (Application Podcast S02E06)
Listen to the full interview in the audio player here, watch the interview video below, where you’ll also find a full transcript of our…
TYPO3 v11 Codesprint Report
- 35 attendees from 6 countries (Poland, Germany, Denmark, India, Netherlands, and Switzerland)
- For 10 people, it was their first time…
Ten Years of News
To make a little noise about the jubilee, I reached out to Georg, who lives in Linz, Austria, to learn more about his decade-long life…
TYPO3 Version 11.4—Into New Galaxies
We are almost there! The TYPO3 v11 release with long-term support is approaching fast. Today we proudly released TYPO3 version 11.4. This version…
Meet Adrian Zimmermann, TYPO3 OG, Switzerland (Application Podcast S02E05)
Listen to the full interview in the audio player here, watch the interview video below, where you’ll also find a full transcript of our…
Structured Content Initiative—What Happened Between November 2020 and August 2021?
The Structured Content Initiative is the core Strategic Initiative focused on improving the content editing user experience in TYPO3…
Extension Award for Documentation
Extensions play an important role for the success of TYPO3. Documentation plays an important role for the success of an extension.
To…
Removal of Community Extensions From forge.typo3.org
In the past, Forge was a place where a community extension could host its issues, news, internal documents, and a wiki. It was also a…
Meet Daniel Homorodean, TYPO3 Expansion Leader, Romania (Application Podcast S2E03)
Listen to the full interview in the audio player here, watch the interview video below, where you’ll also find a full transcript of our…
TYPO3 10.4.20, 9.5.30 and 11.3.3 maintenance releases published
The following TYPO3 updates have been released:
- TYPO3 10.4.20 LTS
- TYPO3 9.5.30 LTS
- TYPO3 11.3.3
These versions are maintenance…
About the Latest TYPO3 Core Security Release
We in the TYPO3 Core Team and Security Team were happy that the release had finally solved this long-standing, severe issue with a…
Report From “QA Best Practices Usable by Community” (August 2021)
The whole outcome, and current process, is available in Gitlab and at Github.
This report will only cover the biggest topics, not every…
TYPO3-EXT-SA-2021-014: SQL Injection in extension "Newsletter" (newsletter)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
TYPO3-EXT-SA-2021-013: Multiple vulnerabilities in Extension "Dated News" (dated_news)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
TYPO3-EXT-SA-2021-012: Cross Site Scripting in Extension "Yoast SEO for TYPO3" (yoast_seo)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
TYPO3-EXT-SA-2021-011: Multiple vulnerabilities in Extension "Miniorange Saml" (miniorange_saml)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
TYPO3-EXT-SA-2021-010: Cross-Site Scripting in Extension "femanager" (femanager)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
TYPO3-EXT-SA-2021-009: Denial of Service in Extension "Deferred image processing" (deferred_image_processing)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …
TYPO3-EXT-SA-2021-008: Sensitive Information Disclosure in “Extbase Yaml Routes” (routes)
- Release Date: August 10, 2021
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. …