Oliver started to work with TYPO3 in 2005 and was fascinated by the product and its universe. Since 2007 he is member of the TYPO3 Core Team. After going back to university in 2014 for achieving a postgraduate master degree in internet web science, he is now researching on advanced web technology topics in general and for TYPO3 in particular. In his spare time, Oliver loves to go cycling cross-country in the uplands around Hof (Germany) in northern Bavaria - at the region where he's living as well.
TYPO3-CORE-SA-2025-013: Unverified Password Change for Backend Users
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.
Read moreTYPO3-CORE-SA-2025-012: Server-Side Request Forgery via Webhooks
It has been discovered that TYPO3 CMS is susceptible to server side request forgery..
TYPO3-CORE-SA-2025-011: Information Disclosure via DBAL Restriction Handling
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3 13.4.8 and 12.4.28 maintenance releases published
The versions 13.4.8 and 12.4.28 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 13.4.4 and 12.4.26 maintenance releases published
The versions 13.4.4 and 12.4.26 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2025-010: Cross-Site Request Forgery in DB Check Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-009: Cross-Site Request Forgery in Scheduler Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-008: Cross-Site Request Forgery in Indexed Search Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-007: Cross-Site Request Forgery in Form Framework Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-006: Cross-Site Request Forgery in Extension Manager Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.