TYPO3-EXT-SA-2025-005: Cross-Site Scripting in extension "[clickstorm] SEO" (cs_seo)
It has been discovered that the extension "[clickstorm] SEO" (cs_seo) is susceptible to Cross-Site Scripting.
Read moreTYPO3-EXT-SA-2025-004: Insecure Direct Object Reference in extension "Download manager" (reint_downloadmanager)
It has been discovered that the extension "Download manager" (reint_downloadmanager) is susceptible to Insecure Direct Object Reference.
TYPO3 9.5.51, 10.4.50, and 11.5.44 ELTS Released
Still sticking to an older version of TYPO3? Today, 9.5.51, 10.4.50 and 11.5.44 have been released. Staying on top of maintenance updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!
TYPO3 Trademark Usage: What’s Allowed and What’s Not
Clear guidelines to support your TYPO3 activities — and protect the brand we all share
TYPO3 13.4.12 and 12.4.31 security releases published
The versions 13.4.12 and 12.4.31 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2025-016: Privilege Escalation to System Maintainer
It has been discovered that TYPO3 CMS is susceptible to broken authentication.
TYPO3-CORE-SA-2025-015: Broken Authentication in Backend MFA
It has been discovered that TYPO3 CMS is susceptible to broken authentication.
TYPO3-CORE-SA-2025-014: Unrestricted File Upload in File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2025-013: Unverified Password Change for Backend Users
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2025-012: Server-Side Request Forgery via Webhooks
It has been discovered that TYPO3 CMS is susceptible to server side request forgery..