<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by author Helmut Hummel</description>
        <language>en</language>
        <link>https://news.typo3.com/article/author/helmut-hummel/blog.author.xml</link>
        <lastBuildDate>Fri, 24 Jul 2026 03:33:28 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3-CORE-SA-2016-022: Cache Flooding in TYPO3 Frontend</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-022</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-022#comments</comments><pubDate>Tue, 13 Sep 2016 12:01:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-022</guid><description>It has been discovered, that TYPO3 is vulnerable to Cache Flooding</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-021: Denial of Service in extension &quot;Speaking URLs for TYPO3&quot; (realurl)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-021</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-021#comments</comments><pubDate>Thu, 08 Sep 2016 10:30:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-021</guid><description>It has been discovered that the extension &quot;Speaking URLs for TYPO3&quot; (realurl) is susceptible to Denial of Service.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-020: Cross-Site Scripting in third party library mso/idna-convert</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-020</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-020#comments</comments><pubDate>Tue, 19 Jul 2016 12:06:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-020</guid><description>It has been discovered, that TYPO3 ships example code of mso/idna-convert library that is vulnerable to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-019: Environment Variable Injection</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-019</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-019#comments</comments><pubDate>Tue, 19 Jul 2016 12:05:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-019</guid><description>It has been discovered, that PHP exposes the risk of Environment Variable Injection and TYPO3 is vulnerable through third party library guzzlehttp/guzzle</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-013: Missing Access Check in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-013</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-013#comments</comments><pubDate>Tue, 24 May 2016 10:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-013</guid><description>It has been discovered, that TYPO3 CMS lacks an access check for Extbase actions.</description></item>


    
        
<item><title>TYPO3-PSA-2016-002: Important Security-Bulletin Pre-Announcement</title><link>https://news.typo3.com/security/advisory/typo3-psa-2016-002</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2016-002#comments</comments><pubDate>Fri, 20 May 2016 11:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2016-002</guid><description>TYPO3 releases containing a fix for a critical vulnerability will be published Tuesday 24th of May at about 10:00 a.m. CEST (08:00 a.m. GMT).</description></item>


    
        
<item><title>TYPO3-PSA-2016-001: Critical vulnerabilities in ImageMagick</title><link>https://news.typo3.com/security/advisory/typo3-psa-2016-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2016-001#comments</comments><pubDate>Thu, 05 May 2016 13:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2016-001</guid><description>Multiple vulnerabilities in ImageMagick have been discovered, Remote Code Execution being one of them.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-012: Privilege Escalation in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-012</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-012#comments</comments><pubDate>Tue, 12 Apr 2016 11:03:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-012</guid><description>It has been discovered, that TYPO3 CMS is vulnerable to Privilege Escalation.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-010: Arbitrary File Disclosure in Form Component</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-010</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-010#comments</comments><pubDate>Tue, 12 Apr 2016 11:01:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-010</guid><description>It has been discovered, that TYPO3 Form Component is susceptible to Arbitrary File Disclosure.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-009: Cross-Site Scripting in TYPO3 Backend</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-009</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-009#comments</comments><pubDate>Tue, 12 Apr 2016 11:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-009</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-004: Cross-Site Scripting in form component</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-004</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-004#comments</comments><pubDate>Tue, 16 Feb 2016 12:04:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-004</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-003: Cross-Site Scripting in legacy form component</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-003</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-003#comments</comments><pubDate>Tue, 16 Feb 2016 12:02:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-003</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-002: Cross-Site Scripting in link validator component</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-002</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-002#comments</comments><pubDate>Tue, 16 Feb 2016 12:01:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-002</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-015: Cross-Site Scripting in TYPO3 component Indexed Search</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-015</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-015#comments</comments><pubDate>Tue, 15 Dec 2015 12:06:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-015</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-009: Non-Persistent Cross-Site Scripting</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-009</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-009#comments</comments><pubDate>Tue, 08 Sep 2015 12:01:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-009</guid><description>It has been discovered, that TYPO3 is susceptible to Non-Persistent Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-008: Unauthenticated Path Disclosure</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-008</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-008#comments</comments><pubDate>Tue, 08 Sep 2015 12:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-008</guid><description>It has been discovered, that TYPO3 is susceptible to unauthenticated path disclosure.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-002: Access bypass when editing file metadata</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-002</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-002#comments</comments><pubDate>Wed, 01 Jul 2015 14:11:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-002</guid><description>It has been discovered, that editors could change, create or delete metadata of files without permission.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-003: Frontend login Session Fixation</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-003</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-003#comments</comments><pubDate>Wed, 01 Jul 2015 14:11:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-003</guid><description>It has been discovered that TYPO3 is susceptible to session fixation.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-004: Cross-Site Scripting in Link Handling &amp; File List</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-004</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-004#comments</comments><pubDate>Wed, 01 Jul 2015 14:11:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-004</guid><description>It has been discovered, that TYPO3 is vulnerable to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-005: Information Disclosure possibility exploitable by Editors</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-005</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-005#comments</comments><pubDate>Wed, 01 Jul 2015 14:11:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-005</guid><description>It has been discovered, that editors could list all files and folders in the root directory of a TYPO3 installation.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-006: Brute Force Protection Bypass in backend login</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-006</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-006#comments</comments><pubDate>Wed, 01 Jul 2015 14:11:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-006</guid><description>It has been discovered, that the backend login brute force protection can be bypassed</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-007: Cross-Site Scripting in 3rd party library Flowplayer</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-007</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-007#comments</comments><pubDate>Wed, 01 Jul 2015 14:11:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-007</guid><description>It has been discovered, that third party component Flowplayer Flash is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>Privilege Escalation in TYPO3 Neos</title><link>https://news.typo3.com/article/typo3-neos-sa-2015-001</link><comments>https://news.typo3.com/article/typo3-neos-sa-2015-001#comments</comments><pubDate>Sat, 28 Mar 2015 08:00:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/article/typo3-neos-sa-2015-001</guid><description>It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2015-001: Authentication Bypass in TYPO3 CMS 4.5</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2015-001</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2015-001#comments</comments><pubDate>Thu, 19 Feb 2015 12:00:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2015-001</guid><description>It has been discovered that TYPO3 CMS 4.5.x is vulnerable to Authentication Bypass.</description></item>


    
        
<item><title>TYPO3-PSA-2015-001: Important Security-Bulletin Pre-Announcement</title><link>https://news.typo3.com/security/advisory/typo3-psa-2015-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2015-001#comments</comments><pubDate>Tue, 17 Feb 2015 12:30:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2015-001</guid><description>A TYPO3 4.5.40 release containing a security fix will be published the day after tomorrow, 
Thursday 19th of February at about 10:00 am CET.
</description></item>


    
        
<item><title>TYPO3-CORE-SA-2014-003: Link spoofing and cache poisoning vulnerabilities in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2014-003</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2014-003#comments</comments><pubDate>Tue, 09 Dec 2014 10:00:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2014-003</guid><description>It has been discovered that TYPO3 CMS is vulnerable to Link Spoofing and Cache Poisoning.</description></item>


    
        
<item><title>TYPO3 CMS 6.0 End of Life Announcement</title><link>https://news.typo3.com/article/typo3-cms-60-end-of-life-announcement</link><comments>https://news.typo3.com/article/typo3-cms-60-end-of-life-announcement#comments</comments><pubDate>Mon, 09 Jun 2014 16:22:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/article/typo3-cms-60-end-of-life-announcement</guid><description>TYPO3 CMS 6.0.14 is the last release for the 6.0.x branch</description></item>


    
        
<item><title>TYPO3-EXT-SA-2014-008: Cross-Site Scripting in gridelements</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2014-008</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2014-008#comments</comments><pubDate>Tue, 27 May 2014 11:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2014-008</guid><description>It has been discovered that the extension &quot;Grid Elements&quot; (gridelements) is susceptible to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2014-001: Multiple Vulnerabilities in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2014-001</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2014-001#comments</comments><pubDate>Thu, 22 May 2014 11:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2014-001</guid><description>It has been discovered that TYPO3 CMS is vulnerable to Cross-Site Scripting, Insecure Unserialize, Improper Session Invalidation, Authentication Bypass, Information Disclosure and Host Spoofing.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2014-005: Access Bypass in extensions &quot;Yet Another Gallery&quot; (yag) and &quot;Tools for Extbase development&quot; (pt_extbase)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2014-005</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2014-005#comments</comments><pubDate>Wed, 12 Feb 2014 12:00:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2014-005</guid><description>It has been discovered that the extensions &quot;Yet Another Gallery&quot; (yag) and &quot;Tools for Extbase development&quot; (pt_extbase) are susceptible to Access Bypass</description></item>


    



    </channel>
</rss>
