Coordinated Security Releases for TYPO3 Extensions
When a security vulnerability is found in a TYPO3 extension, how the fix is released matters as much as the fix itself. Here is why coordinated disclosure through the TYPO3 Security Team is essential for the whole ecosystem.
Read more- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-007: Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
It has been discovered that the extension "E-Mail MFA Provider" (mfa_email) is vulnerable to Authentication Bypass.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-006: Broken Access Control in extension "Redirect Tab" (redirect_tab)
It has been discovered that the extension "Redirect Tab" (redirect_tab) is vulnerable to Broken Access Control.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-005: Insecure Deserialization in extension "Mailqueue" (mailqueue)
It has been discovered that the extension "Mailqueue" (mailqueue) is vulnerable to insecure deserialization.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-004: Vulnerability in bundled package in extension "Amazon AWS SDK" (aws)
It has been discovered that the extension "Amazon AWS SDK" (aws) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-003: Vulnerability in bundled package in extension "Amazon Web Services (AWS) Toolbox" (aws_tools)
It has been discovered that the extension "Amazon Web Services (AWS) Toolbox" (aws_tools) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-002: Vulnerability in bundled package in extension "AWS SDK for PHP" (aws_sdk_php)
It has been discovered that the extension "AWS SDK for PHP" (aws_sdk_php) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2026-001: Insecure Deserialization in extension "Mailqueue" (mailqueue)
It has been discovered that the extension "Mailqueue" (mailqueue) is vulnerable to insecure deserialization.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-016: Vulnerability in bundled package in extension "Single Sign-on with SAML" (md_saml)
It has been discovered that the extension "Single Sign-on with SAML" (md_saml) bundles a vulnerable version of “onelogin/php-saml“ which is susceptible to Authentication Bypass.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-015: Broken Authentication in extension "Modules" (modules)
It has been discovered that the extension "Modules" (modules) is susceptible to Broken Authentication.