<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by date: 2019 / 12</description>
        <language>en</language>
        <link>https://news.typo3.com/article/archive/2019/december/blog.archive.xml</link>
        <lastBuildDate>Tue, 28 Jul 2026 15:18:48 +0200</lastBuildDate>
        
    
    
        
<item><title>Issues You Might Run Into When Upgrading TYPO3 Extensions</title><link>https://news.typo3.com/article/issues-you-might-run-into-when-upgrading-typo3-extensions</link><comments>https://news.typo3.com/article/issues-you-might-run-into-when-upgrading-typo3-extensions#comments</comments><pubDate>Thu, 19 Dec 2019 10:04:00 +0100</pubDate><dc:creator>Frank Nägler</dc:creator><guid>https://news.typo3.com/article/issues-you-might-run-into-when-upgrading-typo3-extensions</guid><description>When considering to upgrade your TYPO3 installation, one of the bigger parts you need to take care of is the upgrade of all installed extensions. Some of them might be your own, others are public extensions.</description><enclosure
            length="818915"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/7/csm_issues_you_might_run_into_when_upgrading_typo3_extensions_header_image_1024dbe0f1.webp" /></item>


    
        
<item><title>TYPO3 v6.2.47 and 7.6.40 ELTS Released</title><link>https://news.typo3.com/article/typo3-v6247-and-7640-elts-released</link><comments>https://news.typo3.com/article/typo3-v6247-and-7640-elts-released#comments</comments><pubDate>Tue, 17 Dec 2019 14:35:00 +0100</pubDate><dc:creator>Andreas Kienast</dc:creator><guid>https://news.typo3.com/article/typo3-v6247-and-7640-elts-released</guid><description>Still sticking to an older version of TYPO3? There may be good reasons for doing so. Today, TYPO3 v6.2.47 and 7.6.40 ELTS have been released. Staying on top of maintenance and security updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!</description><enclosure
            length="1436146"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/8/a/csm_typo3_v6.2.47_and_7.6.40_ELTS_released_header_image_66835067fd.webp" /></item>


    
        
<item><title>TYPO3-EXT-SA-2019-023: CSRF in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-023</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-023#comments</comments><pubDate>Tue, 17 Dec 2019 13:04:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-023</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Cross-Site-Request-Forgery (CSRF).</description></item>


    
        
<item><title>TYPO3-EXT-SA-2019-022: Privilege Escalation in extension &quot;femanager direct mail subscription&quot; (femanager_dmail_subscribe)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-022</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-022#comments</comments><pubDate>Tue, 17 Dec 2019 13:03:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-022</guid><description>It has been discovered that the extension &quot;femanager direct mail subscription&quot; (femanager_dmail_subscribe) is susceptible to Privilege Escalation.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2019-021: Cross Site Scripting in extension &quot;File List&quot; (file_list)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-021</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-021#comments</comments><pubDate>Tue, 17 Dec 2019 13:02:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-021</guid><description>It has been discovered that the extension &quot;File List&quot; (file_list) is susceptible to Cross Site Scripting.
</description></item>


    
        
<item><title>TYPO3-EXT-SA-2019-020: CSRF in extension &quot;Change password for frontend users&quot; (fe_change_pwd)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-020</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-020#comments</comments><pubDate>Tue, 17 Dec 2019 13:01:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-020</guid><description>It has been discovered that the extension &quot;Change password for frontend users&quot; (fe_change_pwd) is susceptible to Cross-Site-Request-Forgery (CSRF).</description></item>


    
        
<item><title>TYPO3-EXT-SA-2019-019: Multiple vulnerabilities in extension &quot;MKSamlAuth&quot; (mksamlauth)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-019</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-019#comments</comments><pubDate>Tue, 17 Dec 2019 12:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2019-019</guid><description>It has been discovered that the extension &quot;MKSamlAuth&quot; (mksamlauth) is susceptible to Broken Authentication and Authentication Bypass.</description></item>


    
        
<item><title>TYPO3 10.2.2, 9.5.13 and 8.7.30 security releases published</title><link>https://news.typo3.com/article/typo3-1022-9513-and-8730-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1022-9513-and-8730-security-releases-published#comments</comments><pubDate>Tue, 17 Dec 2019 11:25:44 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1022-9513-and-8730-security-releases-published</guid><description>The TYPO3 Community announces the versions 10.2.2, 9.5.13 LTS and 8.7.30 LTS of the TYPO3 Enterprise Content Management System.</description><enclosure
            length="6307"
            type="image/svg+xml"
            url="https://news.typo3.com/fileadmin/News/Imported/t3o_common_storage/images/icons/news-dummy-images/News_MinorRelease.svg/News_MinorRelease.svg" /></item>


    
        
<item><title>TYPO3-CORE-SA-2019-026: Insecure Deserialization in Query Generator &amp; Query View</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2019-026</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2019-026#comments</comments><pubDate>Tue, 17 Dec 2019 11:16:57 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2019-026</guid><description>It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2019-025: SQL Injection in low-level Query Generator</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2019-025</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2019-025#comments</comments><pubDate>Tue, 17 Dec 2019 11:13:41 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2019-025</guid><description>It has been discovered that TYPO3 CMS is vulnerable to SQL injection.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2019-024: Directory Traversal on ZIP extraction</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2019-024</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2019-024#comments</comments><pubDate>Tue, 17 Dec 2019 11:09:49 +0100</pubDate><dc:creator>Andreas Fernandez</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2019-024</guid><description>It has been discovered that TYPO3 CMS is vulnerable to directory traversal.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2019-023: Cross-Site Scripting in Filelist Module</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2019-023</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2019-023#comments</comments><pubDate>Tue, 17 Dec 2019 11:05:10 +0100</pubDate><dc:creator>Andreas Fernandez</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2019-023</guid><description>It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2019-022: Cross-Site Scripting in Link Handling</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2019-022</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2019-022#comments</comments><pubDate>Tue, 17 Dec 2019 11:02:15 +0100</pubDate><dc:creator>Frank Nägler</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2019-022</guid><description>It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting in Link Handling.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2019-021: Cross-Site Scripting in Form Framework validation handling</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2019-021</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2019-021#comments</comments><pubDate>Tue, 17 Dec 2019 10:57:26 +0100</pubDate><dc:creator>Frank Nägler</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2019-021</guid><description>It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>TYPO3-PSA-2019-011: Possible Insecure Deserialization in Extbase Request Handling</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-011</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-011#comments</comments><pubDate>Tue, 17 Dec 2019 09:44:28 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-011</guid><description>It has been discovered that TYPO3 CMS can be vulnerable to insecure deserialization.</description></item>


    
        
<item><title>TYPO3-PSA-2019-010: Cross-Site Scripting Vulnerabilities in File Upload Handling</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-010</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-010#comments</comments><pubDate>Tue, 17 Dec 2019 09:44:28 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-010</guid><description>It has been discovered that TYPO3 is susceptible to cross-site scripting.</description></item>


    
        
<item><title>Keep Your TYPO3 v7.6 Site Safe With ELTS</title><link>https://news.typo3.com/article/keep-your-typo3-v76-site-safe-with-elts</link><comments>https://news.typo3.com/article/keep-your-typo3-v76-site-safe-with-elts#comments</comments><pubDate>Thu, 12 Dec 2019 16:35:00 +0100</pubDate><dc:creator>Julian Böhm</dc:creator><guid>https://news.typo3.com/article/keep-your-typo3-v76-site-safe-with-elts</guid><description>Software delivers the most value when fully updated and supported - your enterprise’s CMS is no exception. Keep your TYPO3 v7.6 website safe and increase your return on investment (ROI) by opting for our Extended Long Term Support (ELTS).</description><enclosure
            length="1222309"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/e/5/csm_typo3_elts_7.6_header_image_908eccb5be.webp" /></item>


    
        
<item><title>November 2019: Developer Appreciation Day (DAD)</title><link>https://news.typo3.com/article/november-2019-developer-appreciation-day-dad</link><comments>https://news.typo3.com/article/november-2019-developer-appreciation-day-dad#comments</comments><pubDate>Mon, 09 Dec 2019 02:01:00 +0100</pubDate><dc:creator>Susanne Moog</dc:creator><guid>https://news.typo3.com/article/november-2019-developer-appreciation-day-dad</guid><description>On this Developer Appreciation Day (DAD), we’d like to appreciate all the hard working developers once more who continuously contribute to the TYPO3 Project: Thank you ever so much, folks! Find November&#039;s most important names and some really impressive numbers in our recent post.</description><enclosure
            length="826979"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/e/2/csm_dad_november_2019_header_image_a63c7f0bc7.webp" /></item>


    
        
<item><title>TYPO3 Version 10.2 — Treasure Hunting!</title><link>https://news.typo3.com/article/typo3-version-102-treasure-hunting</link><comments>https://news.typo3.com/article/typo3-version-102-treasure-hunting#comments</comments><pubDate>Tue, 03 Dec 2019 11:00:00 +0100</pubDate><dc:creator>Michael Schams</dc:creator><guid>https://news.typo3.com/article/typo3-version-102-treasure-hunting</guid><description>TYPO3 v10.2 is out now — the last sprint release of the year. A lot of functionality was developed during the TYPO3 Initiative Week (T3INIT19) and TYPO3 v10.2 contains some of these components. We are excited to see that we made a big step forward to shape the next LTS release.</description><enclosure
            length="83623"
            type="image/png"
            url="https://news.typo3.com/fileadmin/_processed_/8/e/csm_v10.2_360x204_pattern_1458d587f2.webp" /></item>


    



    </channel>
</rss>
