<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by author Henning Pingel</description>
        <language>en</language>
        <link>https://news.typo3.com/article/author/henning-pingel/blog.author.xml</link>
        <lastBuildDate>Sat, 12 Sep 2026 05:58:55 +0200</lastBuildDate>
        
    
    
        
<item><title>SECURITY-ISSUES-IN-SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS-INCLUDING-SR-FEUSER-REGISTER: Security issues in several third party TYPO3 extensions including sr_feuser_register</title><link>https://news.typo3.com/security/advisory/security-issues-in-several-third-party-typo3-extensions-including-sr-feuser-register</link><comments>https://news.typo3.com/security/advisory/security-issues-in-several-third-party-typo3-extensions-including-sr-feuser-register#comments</comments><pubDate>Mon, 06 Apr 2009 07:25:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-issues-in-several-third-party-typo3-extensions-including-sr-feuser-register</guid><description>Several vulnerabilities have been found in the following third party TYPO3 extensions: &quot;Frontend User Registration&quot; (sr_feuser_register), &quot;A21glossary Advanced Output&quot; (a21glossary_advanced_output), &quot;ClickStream Analyzer (output)&quot; (alternet_csa_out), &quot;Directory Listing&quot; (dir_listing), &quot;Store Locator&quot; (locator), &quot;Userdata Create/Edit&quot; (sg_userdata), &quot;Versatile Calendar Extension (VCE)&quot; (sk_calendar), &quot;ultraCards&quot; (th_ultracards), &quot;Visitor Tracking&quot; (ws_stats).</description></item>


    
        
<item><title>SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS-CONTAIN-SECURITY-ISSUES: Several third party TYPO3 extensions contain security issues</title><link>https://news.typo3.com/security/advisory/several-third-party-typo3-extensions-contain-security-issues</link><comments>https://news.typo3.com/security/advisory/several-third-party-typo3-extensions-contain-security-issues#comments</comments><pubDate>Thu, 05 Mar 2009 07:30:00 +0100</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/several-third-party-typo3-extensions-contain-security-issues</guid><description>Vulnerabilities have been found in the following third party TYPO3 extensions: &quot;Accessibility Glossary&quot; (a21glossary), &quot;Calendar Base&quot; (cal), &quot;Flat Manager&quot; (flatmgr)</description></item>


    
        
<item><title>SECURITY-ISSUES-IN-SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS: Security issues in  several third party TYPO3 extensions</title><link>https://news.typo3.com/security/advisory/security-issues-in-several-third-party-typo3-extensions</link><comments>https://news.typo3.com/security/advisory/security-issues-in-several-third-party-typo3-extensions#comments</comments><pubDate>Mon, 22 Dec 2008 14:21:00 +0100</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-issues-in-several-third-party-typo3-extensions</guid><description>Security vulnerabilities have been discovered in the following third party TYPO3 extensions: &quot;phpMyAdmin&quot; (phpmyadmin), &quot;DR Wiki - Typo3 Wiki extension&quot; (dr_wiki), &quot;WEC Discussion Forum&quot; (wec_discussion), &quot;Vox populi&quot; (mv_vox_populi), &quot;SB Universal Plugin&quot; (SBuniplug), &quot;Simple File Browser&quot; (simplefilebrowser), &quot;TU-Clausthal ODIN&quot; (tuc_odin), &quot;TU-Clausthal Staff&quot; (tuc_staff), &quot;WEBERkommunal Facilities&quot; (wes_facilities).</description></item>


    
        
<item><title>CROSS-SITE-SCRIPTING-VULNERABILITIES-IN-TYPO3-CORE: Cross Site Scripting vulnerabilities in TYPO3 core</title><link>https://news.typo3.com/security/advisory/cross-site-scripting-vulnerabilities-in-typo3-core</link><comments>https://news.typo3.com/security/advisory/cross-site-scripting-vulnerabilities-in-typo3-core#comments</comments><pubDate>Thu, 13 Nov 2008 07:36:00 +0100</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/cross-site-scripting-vulnerabilities-in-typo3-core</guid><description>It has been discovered that TYPO3 core is susceptible to two Cross Site Scripting (XSS) issues. The frontend plugin of system extension &quot;felogin&quot; and the backend module &quot;file&quot; are vulnerable.</description></item>


    
        
<item><title>SECURITY-ISSUES-IN-TYPO3-EXTENSION-PHPMYADMIN-AND-SEVERAL-OTHER-THIRD-PARTY-EXTENSIONS: Security issues in TYPO3 extension phpMyAdmin and several other third party extensions</title><link>https://news.typo3.com/security/advisory/security-issues-in-typo3-extension-phpmyadmin-and-several-other-third-party-extensions</link><comments>https://news.typo3.com/security/advisory/security-issues-in-typo3-extension-phpmyadmin-and-several-other-third-party-extensions#comments</comments><pubDate>Mon, 10 Nov 2008 07:16:00 +0100</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-issues-in-typo3-extension-phpmyadmin-and-several-other-third-party-extensions</guid><description>Security issues have been discovered in the following third party TYPO3 extensions: &quot;phpMyAdmin&quot; (phpmyadmin), &quot;advCalendar&quot; (advcalendar), &quot;CMS Poll system&quot; (cms_poll), &quot;eLuna Page Comments&quot; (eluna_pagecomments), &quot;Wir ber uns&quot; [sic] (fsmi_people), &quot;Dictionary&quot; (rtgdictionary).</description></item>


    
        
<item><title>SECURITY-ISSUES-IN-TYPO3-EXTENSION-COMMERCE-AND-SEVERAL-OTHER-THIRD-PARTY-EXTENSIONS: Security issues in TYPO3 extension Commerce and several other third party extensions</title><link>https://news.typo3.com/security/advisory/security-issues-in-typo3-extension-commerce-and-several-other-third-party-extensions</link><comments>https://news.typo3.com/security/advisory/security-issues-in-typo3-extension-commerce-and-several-other-third-party-extensions#comments</comments><pubDate>Mon, 20 Oct 2008 08:17:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-issues-in-typo3-extension-commerce-and-several-other-third-party-extensions</guid><description>Security issues have been discovered in the following third party TYPO3 extensions: Commerce (commerce), JobControl (dmmjobcontrol), Econda Plugin (econda), Frontend Users View (feusersview), Mannschaftsliste (kiddog_playerlist), M1 Intern (m1_intern), Simple survey (simplesurvey), Page Improvements (sm_pageimprovements)
</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080527-2-SQL-INJECTION-IN-EXTENSION-LIBRARY-FOR-FRONTEND-PLUGINS-SG-ZFELIB: Security Bulletin TYPO3-20080527-2: SQL Injection in extension &quot;Library for Frontend plugins&quot; (sg_zfelib)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080527-2-sql-injection-in-extension-library-for-frontend-plugins-sg-zfelib</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080527-2-sql-injection-in-extension-library-for-frontend-plugins-sg-zfelib#comments</comments><pubDate>Tue, 27 May 2008 08:15:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080527-2-sql-injection-in-extension-library-for-frontend-plugins-sg-zfelib</guid><description>It has been discovered that the extension &quot;Library for Frontend plugins&quot; (sg_zfelib) is susceptible to SQL Injections.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080527-1-CROSS-SITE-SCRIPTING-VULNERABILITY-IN-EXTENSION-KJ-IMAGE-LIGHTBOX-V2-KJ-IMAGELIGHTBOX2: Security Bulletin TYPO3-20080527-1: Cross Site Scripting vulnerability in extension &quot;KJ: Image Lightbox v2&quot; (kj_imagelightbox2)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080527-1-cross-site-scripting-vulnerability-in-extension-kj-image-lightbox-v2-kj-imagelightbox2</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080527-1-cross-site-scripting-vulnerability-in-extension-kj-image-lightbox-v2-kj-imagelightbox2#comments</comments><pubDate>Tue, 27 May 2008 07:21:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080527-1-cross-site-scripting-vulnerability-in-extension-kj-image-lightbox-v2-kj-imagelightbox2</guid><description>It has been discovered that the extension &quot;KJ: Image Lightbox v2&quot; (kj_imagelightbox2) is susceptible to Cross Site Scripting (XSS) attacks.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080515-2-MULTIPLE-VULNERABILITIES-IN-EXTENSION-FRONTEND-FILEMANAGER-AIR-FILEMANAGER: Security Bulletin TYPO3-20080515-2: Multiple vulnerabilities in extension Frontend Filemanager (air_filemanager)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080515-2-multiple-vulnerabilities-in-extension-frontend-filemanager-air-filemanager</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080515-2-multiple-vulnerabilities-in-extension-frontend-filemanager-air-filemanager#comments</comments><pubDate>Thu, 15 May 2008 07:18:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080515-2-multiple-vulnerabilities-in-extension-frontend-filemanager-air-filemanager</guid><description>It has been discovered that the extension Frontend Filemanager (air_filemanager) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.
</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080515-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-FRONTEND-USER-REGISTRATION-SR-FEUSER-REGISTER: Security Bulletin TYPO3-20080515-1: Multiple vulnerabilities in extension Frontend User Registration (sr_feuser_register)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080515-1-multiple-vulnerabilities-in-extension-frontend-user-registration-sr-feuser-register</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080515-1-multiple-vulnerabilities-in-extension-frontend-user-registration-sr-feuser-register#comments</comments><pubDate>Thu, 15 May 2008 07:16:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080515-1-multiple-vulnerabilities-in-extension-frontend-user-registration-sr-feuser-register</guid><description>It has been discovered that the extension Frontend User Registration (sr_feuser_register) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Command Execution.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080513-4-MULTIPLE-VULNERABILITIES-IN-EXTENSION-STATISTICS-KE-STATS: Security Bulletin TYPO3-20080513-4: Multiple vulnerabilities in extension Statistics (ke_stats)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-4-multiple-vulnerabilities-in-extension-statistics-ke-stats</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-4-multiple-vulnerabilities-in-extension-statistics-ke-stats#comments</comments><pubDate>Tue, 13 May 2008 09:24:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-4-multiple-vulnerabilities-in-extension-statistics-ke-stats</guid><description>It has been discovered that the extension Statistics (ke_stats) is vulnerable to Blind SQL Injection attacks. Also, a Cross Site Scripting issue has been found.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080513-3-CROSS-SITE-SCRIPTING-VULNERABILITY-IN-EXTENSION-EVENT-DATABASE-RLMP-EVENTDB: Security Bulletin TYPO3-20080513-3: Cross Site Scripting vulnerability in extension Event Database (rlmp_eventdb)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-3-cross-site-scripting-vulnerability-in-extension-event-database-rlmp-eventdb</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-3-cross-site-scripting-vulnerability-in-extension-event-database-rlmp-eventdb#comments</comments><pubDate>Tue, 13 May 2008 08:37:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-3-cross-site-scripting-vulnerability-in-extension-event-database-rlmp-eventdb</guid><description>It has been discovered that the extension Event Database (rlmp_eventdb) is susceptible to Cross Site Scripting (XSS) attacks.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080513-2-CROSS-SITE-SCRIPTING-VULNERABILITY-IN-EXTENSION-QUESTIONAIRE-PBSURVEY: Security Bulletin TYPO3-20080513-2: Cross Site Scripting vulnerability in extension Questionaire (pbsurvey)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-2-cross-site-scripting-vulnerability-in-extension-questionaire-pbsurvey</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-2-cross-site-scripting-vulnerability-in-extension-questionaire-pbsurvey#comments</comments><pubDate>Tue, 13 May 2008 08:31:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-2-cross-site-scripting-vulnerability-in-extension-questionaire-pbsurvey</guid><description>It has been discovered that the extension Questionaire (pbsurvey) is susceptible to Cross Site Scripting (XSS) attacks.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080513-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-WT-GALLERY-WT-GALLERY: Security Bulletin TYPO3-20080513-1: Multiple vulnerabilities in extension WT Gallery (wt_gallery)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-1-multiple-vulnerabilities-in-extension-wt-gallery-wt-gallery</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-1-multiple-vulnerabilities-in-extension-wt-gallery-wt-gallery#comments</comments><pubDate>Tue, 13 May 2008 08:25:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080513-1-multiple-vulnerabilities-in-extension-wt-gallery-wt-gallery</guid><description>It has been discovered that the extension WT Gallery (wt_gallery) is susceptible to Path Traversal and Cross Site Scripting (XSS) attacks. Besides that, it may disclose sensitive information.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080505-2-CROSS-SITE-SCRIPTING-VULNERABILITY-IN-EXTENSION-POWERMAIL: Security Bulletin TYPO3-20080505-2: Cross Site Scripting vulnerability in extension powermail</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080505-2-cross-site-scripting-vulnerability-in-extension-powermail</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080505-2-cross-site-scripting-vulnerability-in-extension-powermail#comments</comments><pubDate>Mon, 05 May 2008 07:18:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080505-2-cross-site-scripting-vulnerability-in-extension-powermail</guid><description>It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080505-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-MAILFORMPLUS-TH-MAILFORMPLUS: Security Bulletin TYPO3-20080505-1: Multiple vulnerabilities in extension MailformPlus (th_mailformplus)</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080505-1-multiple-vulnerabilities-in-extension-mailformplus-th-mailformplus</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080505-1-multiple-vulnerabilities-in-extension-mailformplus-th-mailformplus#comments</comments><pubDate>Mon, 05 May 2008 07:14:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080505-1-multiple-vulnerabilities-in-extension-mailformplus-th-mailformplus</guid><description>It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080416-2-SQL-INJECTIONS-IN-EXTENSIONS-PMK-RSSNEWSEXPORT-AND-CM-RDFEXPORT: Security Bulletin TYPO3-20080416-2: SQL Injections in extensions pmk_rssnewsexport and cm_rdfexport</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080416-2-sql-injections-in-extensions-pmk-rssnewsexport-and-cm-rdfexport</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080416-2-sql-injections-in-extensions-pmk-rssnewsexport-and-cm-rdfexport#comments</comments><pubDate>Wed, 16 Apr 2008 07:32:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080416-2-sql-injections-in-extensions-pmk-rssnewsexport-and-cm-rdfexport</guid><description>It has been discovered that the extensions pmk_rssnewsexport and cm_rdfexport are vulnerable to SQL Injection attacks.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080416-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-DE-PHPOT: Security Bulletin TYPO3-20080416-1: Multiple vulnerabilities in extension de_phpot</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080416-1-multiple-vulnerabilities-in-extension-de-phpot</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080416-1-multiple-vulnerabilities-in-extension-de-phpot#comments</comments><pubDate>Wed, 16 Apr 2008 07:05:00 +0200</pubDate><dc:creator>Henning Pingel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080416-1-multiple-vulnerabilities-in-extension-de-phpot</guid><description>It has been discovered that the extension de_phpot is vulnerable to multiple SQL Injection flaws and other types of security issues.</description></item>


    



    </channel>
</rss>
