TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
It has been discovered that the extension "OpenID Connect Authentication" (oidc) is susceptible to Account Takeover.
Read moreRoadmap for TYPO3 v14 — the High-Level Objectives and Strategic Goals
TYPO3 v14 LTS is scheduled for release at the end of April 2026. The Product Strategy Group has plans for ground-breaking changes to our favorite CMS. With your help, it will be the most significant release in years.
Annual Report of the TYPO3 Documentation Team
The TYPO3 Documentation Team made significant strides in 2024, achieving groundbreaking advancements and key improvements. Let’s explore the accomplishments and contributions that defined this transformative year.
TYPO3 13.4.4 and 12.4.26 maintenance releases published
The versions 13.4.4 and 12.4.26 of the TYPO3 Enterprise Content Management System have just been released.
Visitors From the Symfony World Contribute To TYPO3 Documentation Search Frontend
When the much-improved functionality at docs.typo3.org was implemented, it still missed a nice-looking frontend. That work was completed by two French companies from the Symfony world. Here’s their story.
TYPO3-CORE-SA-2025-010: Cross-Site Request Forgery in DB Check Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-009: Cross-Site Request Forgery in Scheduler Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-008: Cross-Site Request Forgery in Indexed Search Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-007: Cross-Site Request Forgery in Form Framework Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-006: Cross-Site Request Forgery in Extension Manager Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.