This Month in TYPO3: August, 2026
August was a governance month. The Association opened its proposed Rules for TYPO3 Units to community review, introduced an independent mediation service for Code of Conduct support, and put six Round Three budget ideas to a member vote.
Read moreTYPO3 Contribution in Numbers: August 2026
See the full recap of TYPO3's August core contributions with 80 contributors, 148 reviews, bug fixes, features, and a big thank-you to our developers.
Notes From the Q&A on External Mediation and Support
The online meeting answered community questions about how the new, independent external mediation service will operate. If you were unable to attend the live webinar, the full video recording is now available.
What Changes, What Endures: Notes From CMS Connect 2026
On 4–5 August 2026, I traveled to Canada to attend and speak at CMS Connect 26, an international industry conference run by Janus Boye.
TYPO3 Association Board Meeting Protocol (19 August 2026)
The TYPO3 Association Board reviewed ongoing governance and compliance work, including the Conflict of Interest Policy and preparations for the Cyber Resilience Act. The meeting also covered new community structures and potential partnerships.
TYPO3-EXT-SA-2026-027: SQL Injection in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)
It has been discovered that the extension "Events 2" (events2) is susceptible to two instances of Broken Access Control.
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
It has been discovered that the extension "Apache Solr for TYPO3 - Enterprise Search" (solr) is vulnerable to Broken Access Control, Insecure Deserialization and Information Disclosure.
TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is vulnerable to Broken Access Control and Information Disclosure.
TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
It has been discovered that the extension "Event management and registration" (sf_event_mgt) is vulnerable to Broken Access Control and Server-Side Template Injection (SSTI).