- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2015-006: Brute Force Protection Bypass in backend login
It has been discovered, that the backend login brute force protection can be bypassed
Read more- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2015-007: Cross-Site Scripting in 3rd party library Flowplayer
It has been discovered, that third party component Flowplayer Flash is vulnerable to cross-site scripting.
Privilege Escalation in TYPO3 Neos
It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation.
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2015-001: Authentication Bypass in TYPO3 CMS 4.5
It has been discovered that TYPO3 CMS 4.5.x is vulnerable to Authentication Bypass.
- The Project
- Security / Public Service Announcement
TYPO3-PSA-2015-001: Important Security-Bulletin Pre-Announcement
A TYPO3 4.5.40 release containing a security fix will be published the day after tomorrow, Thursday 19th of February at about 10:00 am CET.
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2014-003: Link spoofing and cache poisoning vulnerabilities in TYPO3 CMS
It has been discovered that TYPO3 CMS is vulnerable to Link Spoofing and Cache Poisoning.
TYPO3 CMS 6.0 End of Life Announcement
TYPO3 CMS 6.0.14 is the last release for the 6.0.x branch
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2014-008: Cross-Site Scripting in gridelements
It has been discovered that the extension "Grid Elements" (gridelements) is susceptible to Cross-Site Scripting
- Product Updates & Roadmap
- Security / TYPO3 CMS
TYPO3-CORE-SA-2014-001: Multiple Vulnerabilities in TYPO3 CMS
It has been discovered that TYPO3 CMS is vulnerable to Cross-Site Scripting, Insecure Unserialize, Improper Session Invalidation, Authentication Bypass, Information Disclosure and Host Spoofing.
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2014-005: Access Bypass in extensions "Yet Another Gallery" (yag) and "Tools for Extbase development" (pt_extbase)
It has been discovered that the extensions "Yet Another Gallery" (yag) and "Tools for Extbase development" (pt_extbase) are susceptible to Access Bypass