Oliver started to work with TYPO3 in 2005 and was fascinated by the product and its universe. Since 2007 he is member of the TYPO3 Core Team. After going back to university in 2014 for achieving a postgraduate master degree in internet web science, he is now researching on advanced web technology topics in general and for TYPO3 in particular. In his spare time, Oliver loves to go cycling cross-country in the uplands around Hof (Germany) in northern Bavaria - at the region where he's living as well.
TYPO3-CORE-SA-2023-006: Weak Authentication in Session Handling
It has been discovered that TYPO3 CMS is susceptible to weak authentication.
Read moreTYPO3-CORE-SA-2023-005: Information Disclosure in Install Tool
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3 12.4.8 and 11.5.33 security releases published
The versions 12.4.8 and 11.5.33 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 12.4.7 and 11.5.32 maintenance releases published
The versions 12.4.7 and 11.5.32 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2023-004: Cross-Site Scripting in CKEditor4 WordCount Plugin
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2023-003: Information Disclosure due to Out-of-scope Site Resolution
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2023-002: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3 12.4.4 and 11.5.30 security releases published
The versions 12.4.4 and 11.5.30 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 12.2.0, 11.5.23 and 10.4.36 security releases published
The versions 12.2.0, 11.5.23 and 10.4.36 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2023-001: Persisted Cross-Site Scripting in Frontend Rendering
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.