TYPO3 News & Events Hub
What’s New & What’s Coming
TYPO3-EXT-SA-2026-013: Remote Code Execution in extension "Content Element Selector" (ceselector)
It has been discovered that the extension "Content Element Selector" (ceselector) is vulnerable to Remote Code Execution.
Read moreTYPO3-EXT-SA-2026-012: SQL Injection in extension "Address List" (tt_address)
It has been discovered that the extension "Address List" (tt_address) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-011: Multiple vulnerabilities in extension "Faceted Search" (ke_search)
It has been discovered that the extension "Faceted Search" (ke_search) is vulnerable to XML External Entity injection, Path Traversal and Information Disclosure.
TYPO3-EXT-SA-2026-010: SQL Injection in extension "News system" (news)
It has been discovered that the extension "News system" (news) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-009: Broken Access Control in extension "Frontend User Registration" (sf_register)
It has been discovered that the extension "Frontend User Registration" (sf_register) is vulnerable to Broken Access Control.
TYPO3-EXT-SA-2026-008: Remote Code Execution in extension "Site Crawler" (crawler)
It has been discovered that the extension "Site Crawler" (crawler) is vulnerable to Remote Code Execution.
Changes to the TYPO3 Bug Bounty Program
Extension security reporting continues — financial rewards for extension findings will end on 31 May 2026.
SEAL Extension Takes the Next Step: Advanced Search, GEO Features and AI Vector Integration
In this update, Tim Lochmüller reports on his Q1/2026 Community Budget project, confirming that all three milestones of the SEAL ecosystem expansion — covering advanced search, geographical features, and AI vector integration — have been successfully reached.
The Next Wave of TYPO3
At TYPO3 Surf Camp in Fuerteventura, a new generation of contributors is stepping forward. Reflections on mentorship, community, and the future of TYPO3.
TYPO3 14.3.1 and 13.4.29 maintenance releases published
The versions 14.3.1 and 13.4.29 of the TYPO3 Enterprise Content Management System have just been released.