TYPO3-SA-2010-007: Cross-Site Scripting vulnerability in extension mm_forum (mm_forum)
It has been discovered that the extension mm_forum (mm_forum) is vulnerable to Cross-Site Scripting.
Read moreTYPO3-SA-2010-006: Multiple vulnerabilities in third party extensions
Several vulnerabilities have been found in the following third party TYPO3 extensions: Brainstorming (brainstorming), Power Extension Manager (ch_lightem), Sellector.com Widget Integration (chsellector), Educator (educator), MK Wastebasket (mk_wastebasket), myDashboard (mydashboard), CleanDB (nf_cleandb), Diocese of Portsmouth Database (pd_diocesedatabase), Reports Logfile View (reports_logview), SAV Filter Alphabetic (sav_filter_abc), SAV Filter Selectors (sav_filter_selectors), SAV Filter Months (sav_filter_months), Book Reviews (sk_bookreview), Simple Gallery (sk_simplegallery), Typo3 Quixplorer (t3quixplorer), TYPO3 Security - Salted user password hashes (t3sec_saltedpw), UserTask Center, recent (taskcenter_recent), TGM-Newsletter (tgm_newsletter), CleanDB - DBAL (tmsw_cleandb), Meet Travelmates (travelmate), YATSE - Yet another TYPO3 search engine (yatse)
SECURITY-ISSUES-IN-SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS-INCLUDING-MM-FORUM-MM-FORUM: Security issues in several third party TYPO3 extensions including "mm_forum" (mm_forum)
A security vulnerabilities has been discovered in the third party TYPO3 extensions including mm_forum, brainstorming, ch_lightem, chsellector, educator, mk_wastebasket, mydashboard, nf_cleandb, pd_diocesedatabase, reports_logview, sav_filter_abc, sav_filter_selectors, sav_filter_months, sk_bookreview, sk_simplegallery, t3quixplorer, t3sec_saltedpw, taskcenter_recent, tgm_newsletter, tmsw_cleandb, travelmate, yatse
The Bug Days are back!
The Bug Days went dormant for a couple of months, but they're not dead! Join us on Friday, March 26th.
Extbase Quickstart Documentation Released
Google Summer of Code 2010 coming up
TYPO3-SA-2010-005: Blind SQL Injection vulnerability in extension Calendar Base (cal)
It has been discovered that the extension Calendar Base (cal) is vulnerable to Blind SQL Injection.
SECURITY-ISSUE-IN-THIRD-PARTY-TYPO3-EXTENSION-CALENDAR-BASE-CAL: Security issue in third party TYPO3 extension "Calendar Base" (cal)
A security vulnerabilitiy has been discovered in the third party TYPO3 extension "Calendar Base".
"What ever happened to..." the results of T3UXW09?
You might have heard of last years' TYPO3 coding week "TYPO3 User eXperience Week" where 30 TYPO3 enthusiasts met in a castle to bring TYPO3 closer to the user. This meant that these coders, designers and managers worked on all the things the user is confronted with in the TYPO3 4.x Backend. Thus, the main goal was to increase the user experience for the every-day user.
Release of TYPO3 4.4alpha1 and the current status
Today, the TYPO3 community released the first alpha version of TYPO3 4.4. Although it's far from a final release, which is scheduled for a release in mid June, we're doing a lot of fine tuning and groundwork. You can consider this alpha version as a "developer snapshot" to try out and play around.