TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-013: Broken Access Control in Media Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-012: Broken Access Control in DataHandler
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-011: Broken Access Control in Recycler
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-010: Cross-Site Scripting in Indexed Search
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2026-009: Open Redirect in TYPO3 CMS
It has been discovered that TYPO3 CMS is susceptible to open redirect.
TYPO3-CORE-SA-2026-008: Broken Access Control in Form Framework
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-007: Broken Access Control in File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2026-006: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2026-013: Remote Code Execution in extension "Content Element Selector" (ceselector)
It has been discovered that the extension "Content Element Selector" (ceselector) is vulnerable to Remote Code Execution.
TYPO3-EXT-SA-2026-012: SQL Injection in extension "Address List" (tt_address)
It has been discovered that the extension "Address List" (tt_address) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-011: Multiple vulnerabilities in extension "Faceted Search" (ke_search)
It has been discovered that the extension "Faceted Search" (ke_search) is vulnerable to XML External Entity injection, Path Traversal and Information…
TYPO3-EXT-SA-2026-010: SQL Injection in extension "News system" (news)
It has been discovered that the extension "News system" (news) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-009: Broken Access Control in extension "Frontend User Registration" (sf_register)
It has been discovered that the extension "Frontend User Registration" (sf_register) is vulnerable to Broken Access Control.
TYPO3-EXT-SA-2026-008: Remote Code Execution in extension "Site Crawler" (crawler)
It has been discovered that the extension "Site Crawler" (crawler) is vulnerable to Remote Code Execution.
Editors Choice: The Top 5 Editor-friendly Features in TYPO3 v14 LTS
Discover the top 5 editor-friendly features in TYPO3 v14 LTS. From a redesigned backend to smarter workflows and guided translations. Content editing…
Members Have Selected Four Ideas to be Funded in Round Two 2026
The TYPO3 Association member poll for Round Two in 2026 budget ideas has finished. This time four winning ideas will be funded by the TYPO3…
Hybrid Marketing Sprint for Version 14
From the sunny shores of Fuerteventura to the creative hub of Berlin, the latest TYPO3 Marketing Sprint took our collaboration to a new level. In a…
Coordinated Security Releases for TYPO3 Extensions
When a security vulnerability is found in a TYPO3 extension, how the fix is released matters as much as the fix itself. Here is why coordinated…
TYPO3 v14 LTS—The Next Generation
Today, we are thrilled to announce TYPO3 v14 LTS, our latest flagship release and a major milestone in TYPO3's evolution. This new era begins with a…
TYPO3-CORE-SA-2026-005: Cleartext storage of Backend User Passwords
It has been discovered that TYPO3 CMS is susceptible to sensitive data exposure.
Cleartext storage of Backend User Passwords
It has been discovered that TYPO3 CMS is susceptible to sensitive data exposure.
Unsuccessful Third Election Round for TYPO3 Association Board
None of the remaining candidates achieved 50% of the votes. The election is therefore deemed unsuccessful and the board will have only six members.
What's New in DDEV for TYPO3 Developers
DDEV has shipped a series of updates with real benefits for TYPO3 developers. This roundup covers the highlights: Improved ddev share with TYPO3…
tp3ratings – Ihre Plattform für modernes Bewertungsmanagement
Kundenbewertungen sind heute einer der wichtigsten Faktoren für Vertrauen, Sichtbarkeit und Kaufentscheidungen. Unternehmen sammeln Bewertungen auf unterschiedlichsten Plattformen – von Google über Branchenverzeichnisse bis hin zu spezialisierten Portalen (Doclib, Kenstdueinen,…) Doch häufig bleiben diese wertvollen Inhalte verstreut und können nicht optimal genutzt werden.
ratings.tp3.de bündelt Bewertungen aus verschiedenen Quellen, analysiert sie automatisiert und bereitet sie für die weitere Nutzung auf. So entsteht aus einzelnen Kundenmeinungen ein zentraler, strukturierter und verwertbarer Datenbestand.