- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-014: Vulnerability in bundled package in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) bundles a vulnerable version of "phpoffice/phpspreadsheet", which is susceptible to Server-Side Request Forgery.
Read more- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-013: Vulnerability in bundled package in extension "Base Excel" (base_excel)
It has been discovered that the extension "Base Excel" (base_excel) bundles a vulnerable version of “phpoffice/phpspreadsheet“ which is susceptible to Server-Side Request Forgery.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-012: Cross-Site Scripting in extension "Form to Database" (form_to_database)
It has been discovered that the extension "Form to Database" (form_to_database) is susceptible to Cross-Site Scripting.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-011: Command Injection in extension "TYPO3 Backup Plus" (ns_backup)
It has been discovered that the extension "TYPO3 Backup Plus" (ns_backup) is susceptible to Command Injection.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-010: Insecure Direct Object Reference in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Insecure Direct Object Reference.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-009: Insecure Direct Object Reference in extension "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-003: Multiple vulnerabilities in extension “[clickstorm] SEO” (cs_seo)
It has been discovered that the extension "[clickstorm] SEO" (cs_seo) is susceptible to Cross-Site Scripting and Insecure Direct Object Reference.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-002: Cross-Site Scripting in extension “Additional TCA” (additional_tca)
It has been discovered that the extension “Additional TCA” (additional_tca) is susceptible to Cross-Site Scripting.
- Developer & Technology
- Security / TYPO3 Extensions
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
It has been discovered that the extension "OpenID Connect Authentication" (oidc) is susceptible to Account Takeover.
Double bug bounties for vulnerabilities in TYPO3 CMS until the end of 2024
The TYPO3 Security Team is doubling bug bounties for all verified vulnerabilities in TYPO3 CMS until December 31, 2024. This special campaign offers an opportunity for security researchers and ethical hackers to contribute to TYPO3’s security with enhanced rewards in recognition of their efforts.