Oliver started to work with TYPO3 in 2005 and was fascinated by the product and its universe. Since 2007 he is member of the TYPO3 Core Team. After going back to university in 2014 for achieving a postgraduate master degree in internet web science, he is now researching on advanced web technology topics in general and for TYPO3 in particular. In his spare time, Oliver loves to go cycling cross-country in the uplands around Hof (Germany) in northern Bavaria - at the region where he's living as well.
TYPO3-CORE-SA-2025-017: Open Redirect in TYPO3 CMS
It has been discovered that TYPO3 CMS is susceptible to open redirect.
Read moreTYPO3 13.4.18 and 12.4.37 security releases published
The versions 13.4.18 and 12.4.37 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-PSA-2025-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
TYPO3 13.4.17 and 12.4.36 maintenance releases published
The versions 13.4.17 and 12.4.36 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 13.4.14 and 12.4.33 maintenance releases published
The versions 13.4.14 and 12.4.33 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 13.4.13 and 12.4.32 maintenance releases published
The versions 13.4.13 and 12.4.32 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 13.4.12 and 12.4.31 security releases published
The versions 13.4.12 and 12.4.31 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2025-016: Privilege Escalation to System Maintainer
It has been discovered that TYPO3 CMS is susceptible to broken authentication.
TYPO3-CORE-SA-2025-015: Broken Authentication in Backend MFA
It has been discovered that TYPO3 CMS is susceptible to broken authentication.
TYPO3-CORE-SA-2025-014: Unrestricted File Upload in File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.