Bringing Fluid to VSCode
A first-party VSCode extension now provides deep integration for Fluid templates in the IDE, improving the developer experience for TYPO3 workflows.
Read moreTYPO3-EXT-SA-2026-013: Remote Code Execution in extension "Content Element Selector" (ceselector)
It has been discovered that the extension "Content Element Selector" (ceselector) is vulnerable to Remote Code Execution.
TYPO3-EXT-SA-2026-012: SQL Injection in extension "Address List" (tt_address)
It has been discovered that the extension "Address List" (tt_address) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-011: Multiple vulnerabilities in extension "Faceted Search" (ke_search)
It has been discovered that the extension "Faceted Search" (ke_search) is vulnerable to XML External Entity injection, Path Traversal and Information Disclosure.
TYPO3-EXT-SA-2026-010: SQL Injection in extension "News system" (news)
It has been discovered that the extension "News system" (news) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-009: Broken Access Control in extension "Frontend User Registration" (sf_register)
It has been discovered that the extension "Frontend User Registration" (sf_register) is vulnerable to Broken Access Control.
TYPO3-EXT-SA-2026-008: Remote Code Execution in extension "Site Crawler" (crawler)
It has been discovered that the extension "Site Crawler" (crawler) is vulnerable to Remote Code Execution.
SEAL Extension Takes the Next Step: Advanced Search, GEO Features and AI Vector Integration
In this update, Tim Lochmüller reports on his Q1/2026 Community Budget project, confirming that all three milestones of the SEAL ecosystem expansion — covering advanced search, geographical features, and AI vector integration — have been successfully reached.
TYPO3 Contribution in Numbers: April 2026
See the full recap of TYPO3's April core contributions with 71 contributors, 214 reviews, bug fixes, features, and a big thank-you to our developers.
Coordinated Security Releases for TYPO3 Extensions
When a security vulnerability is found in a TYPO3 extension, how the fix is released matters as much as the fix itself. Here is why coordinated disclosure through the TYPO3 Security Team is essential for the whole ecosystem.