<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by author Marcus Krause</description>
        <language>en</language>
        <link>https://news.typo3.com/article/author/marcus-krause/blog.author.xml</link>
        <lastBuildDate>Fri, 24 Jul 2026 03:30:59 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3-EXT-SA-2025-008: Multiple vulnerabilities in extension &quot;Front End User Registration&quot; (sr_feuser_register)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-008</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-008#comments</comments><pubDate>Tue, 20 May 2025 12:04:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-008</guid><description>It has been discovered that the extension &quot;Front End User Registration&quot; (sr_feuser_register) is susceptible to Remote Code Execution and Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-007: Multiple vulnerabilities in extension &quot;Backup Plus&quot; (ns_backup)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-007</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-007#comments</comments><pubDate>Tue, 20 May 2025 12:03:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-007</guid><description>It has been discovered that the extension &quot;Backup Plus&quot; (ns_backup) is susceptible to Command Injection, Predictable Resource Location and Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-006: Insecure Direct Object Reference in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-006</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-006#comments</comments><pubDate>Tue, 20 May 2025 12:02:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-006</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-005: Cross-Site Scripting in extension &quot;[clickstorm] SEO&quot; (cs_seo)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-005</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-005#comments</comments><pubDate>Tue, 20 May 2025 12:01:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-005</guid><description>It has been discovered that the extension &quot;[clickstorm] SEO&quot; (cs_seo) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-004: Insecure Direct Object Reference in extension &quot;Download manager&quot; (reint_downloadmanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-004</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-004#comments</comments><pubDate>Tue, 20 May 2025 12:00:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-004</guid><description>It has been discovered that the extension &quot;Download manager&quot; (reint_downloadmanager) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-PSA-2021-003: Mitigation of Cache Poisoning Caused by Untrusted URL Query Parameters</title><link>https://news.typo3.com/security/advisory/typo3-psa-2021-003</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2021-003#comments</comments><pubDate>Thu, 16 Dec 2021 12:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2021-003</guid><description>It has been discovered that TYPO3 CMS is susceptible to cache poisoning.
</description></item>


    
        
<item><title>TYPO3-CORE-SA-2017-003: Cross-Site Scripting in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2017-003</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2017-003#comments</comments><pubDate>Tue, 28 Feb 2017 11:01:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2017-003</guid><description>It has been discovered, that TYPO3 is vulnerable to Cross-Site Scripting</description></item>


    
        
<item><title>TYPO3-CORE-SA-2017-002: Authentication Bypass in TYPO3 Frontend</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2017-002</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2017-002#comments</comments><pubDate>Tue, 28 Feb 2017 11:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2017-002</guid><description>It has been discovered, that TYPO3 CMS is vulnerable to Authentication Bypass.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2017-001: Remote Code Execution in third party library swiftmailer</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2017-001</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2017-001#comments</comments><pubDate>Tue, 03 Jan 2017 12:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2017-001</guid><description>It has been discovered, that the third party package swiftmailer/swiftmailer is vulnerable to Remote Code Execution</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-024: Path Traversal in TYPO3 Core</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-024</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-024#comments</comments><pubDate>Tue, 22 Nov 2016 12:01:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-024</guid><description>It has been discovered, that TYPO3 is susceptible to Path Traversal.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-023: Insecure Unserialize in TYPO3 Backend</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-023</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-023#comments</comments><pubDate>Tue, 22 Nov 2016 12:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-023</guid><description>It has been discovered, that TYPO3 is susceptible to Insecure Unserialize.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-033: Unvalidated Redirect in extension &quot;TC Directmail&quot; (tcdirectmail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-033</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-033#comments</comments><pubDate>Mon, 14 Nov 2016 12:05:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-033</guid><description>It has been discovered that the extension &quot;TC Directmail&quot; (tcdirectmail) is susceptible to Unvalidated Redirect.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-032: SQL Injection in extension &quot;Member Infosheets&quot; (if_membersheet)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-032</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-032#comments</comments><pubDate>Mon, 14 Nov 2016 12:04:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-032</guid><description>It has been discovered that the extension &quot;Member Infosheets&quot; (if_membersheet) is susceptible to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-031: Cross Site-Scripting in extension &quot;Secure Download Form&quot; (rs_securedownload)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-031</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-031#comments</comments><pubDate>Mon, 14 Nov 2016 12:03:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-031</guid><description>It has been discovered that the extension &quot;Secure Download Form&quot; (rs_securedownload) is susceptible to Cross Site-Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-030: SQL Injection in extension &quot;Shibboleth Authentication&quot; (shibboleth_auth)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-030</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-030#comments</comments><pubDate>Mon, 14 Nov 2016 12:02:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-030</guid><description>It has been discovered that the extension &quot;Shibboleth Authentication&quot; (shibboleth_auth) is susceptible to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-029: Insecure Unserialize and SQL Injection in extension &quot;Code Highlighter&quot; (mh_code_highlighter)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-029</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-029#comments</comments><pubDate>Mon, 14 Nov 2016 12:01:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-029</guid><description>It has been discovered that the extension &quot;Code Highlighter&quot; (mh_code_highlighter) is susceptible to Insecure Unserialize and SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-028: Cross-Site Scripting in extension &quot;Store Locator&quot; (locator)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-028</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-028#comments</comments><pubDate>Mon, 14 Nov 2016 12:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-028</guid><description>It has been discovered that the extension &quot;Store Locator&quot; (locator) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-027: Cross-Site Scripting in extension &quot;HTML5 Video Player&quot; (html5videoplayer)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-027</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-027#comments</comments><pubDate>Fri, 11 Nov 2016 12:01:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-027</guid><description>It has been discovered that the extension &quot;HTML5 Video Player&quot; (html5videoplayer) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-026: Multiple vulnerabilities in extension &quot;TC Directmail &quot; (tcdirectmail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-026</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-026#comments</comments><pubDate>Fri, 11 Nov 2016 12:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-026</guid><description>It has been discovered that the extension &quot;TC Directmail &quot; (tcdirectmail) is susceptible to Cross Site-Scripting and SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-025: Multiple vulnerabilities in extension &quot;phpMyAdmin&quot; (phpmyadmin)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-025</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-025#comments</comments><pubDate>Thu, 29 Sep 2016 12:02:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-025</guid><description>It has been discovered that the extension &quot;phpMyAdmin&quot; (phpmyadmin) has multiple vulnerabilities.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-024: SQL Injection in extension &quot;Events&quot; (jp_events)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-024</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-024#comments</comments><pubDate>Thu, 29 Sep 2016 12:01:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-024</guid><description>It has been discovered that the extension &quot;Events&quot; (jp_events) is susceptible to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-023: SQL Injection in extension &quot;GN Tactics Planner&quot; (sf_gntactics)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-023</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-023#comments</comments><pubDate>Thu, 29 Sep 2016 12:00:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-023</guid><description>It has been discovered that the extension &quot;GN Tactics Planner&quot; (sf_gntactics) is susceptible to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-022: Arbitrary Code Execution in extension &quot;Frontend User Registration&quot; (sf_register)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-022</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-022#comments</comments><pubDate>Mon, 12 Sep 2016 12:00:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-022</guid><description></description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-018: Cross-Site Scripting vulnerability in typolinks</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-018</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-018#comments</comments><pubDate>Tue, 19 Jul 2016 12:04:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-018</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-017: Information Disclosure in TYPO3 Backend</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-017</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-017#comments</comments><pubDate>Tue, 19 Jul 2016 12:03:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-017</guid><description>It has been discovered, that TYPO3 is susceptible to Information Disclosure.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-016: SQL Injection in TYPO3 Frontend Login</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-016</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-016#comments</comments><pubDate>Tue, 19 Jul 2016 12:02:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-016</guid><description>It has been discovered, that TYPO3 is susceptible to SQL Injection.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-015: Insecure Unserialize in TYPO3 Import/Export</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-015</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-015#comments</comments><pubDate>Tue, 19 Jul 2016 12:01:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-015</guid><description>It has been discovered, that TYPO3 is susceptible to Insecure Unserialize.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2016-014: Cross-Site Scripting in TYPO3 Backend</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2016-014</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2016-014#comments</comments><pubDate>Tue, 19 Jul 2016 12:00:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2016-014</guid><description>It has been discovered, that TYPO3 is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-020: Insecure Unserialize  in extension &quot;Page path&quot; (pagepath)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-020</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-020#comments</comments><pubDate>Thu, 07 Jul 2016 12:01:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-020</guid><description>It has been discovered that the extension &quot;Page path&quot; (pagepath) is susceptible to Insecure Unserialize.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2016-019: Cross-Site Scripting in extension &quot;CCDebug&quot; (cc_debug)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-019</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-019#comments</comments><pubDate>Thu, 07 Jul 2016 12:00:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2016-019</guid><description>It has been discovered that the extension &quot;CCDebug&quot; (cc_debug) is susceptible to Cross-Site Scripting.</description></item>


    



    </channel>
</rss>
