TYPO3 Contribution in Numbers: April 2026
See the full recap of TYPO3's April core contributions with 71 contributors, 214 reviews, bug fixes, features, and a big thank-you to our developers.
Read moreCoordinated Security Releases for TYPO3 Extensions
When a security vulnerability is found in a TYPO3 extension, how the fix is released matters as much as the fix itself. Here is why coordinated disclosure through the TYPO3 Security Team is essential for the whole ecosystem.
TYPO3-CORE-SA-2026-005: Cleartext storage of Backend User Passwords
It has been discovered that TYPO3 CMS is susceptible to sensitive data exposure.
What's New in DDEV for TYPO3 Developers
DDEV has shipped a series of updates with real benefits for TYPO3 developers. This roundup covers the highlights: Improved ddev share with TYPO3 hooks, a new dashboard, better Windows installation, new diagnostic utilities, and rootless container support.
Improving Fluid Developer Experience with TYPO3 v14
Simon Praetorius gives us an update on his Community Budget idea for improving the Fluid developer experience — and the first results are already landing in Fluid 5.2.
TYPO3 Contribution in Numbers: March 2026
See the full recap of TYPO3's March core contributions with 66 contributors, 255 reviews, bug fixes, features, and a big thank-you to our developers.
TYPO3 and its Accessibility in the Backend — Changes from v6 to v14
A look at how the TYPO3 community has tackled backend accessibility over the years — and what a dedicated sprint in 2025 revealed about how far it's come, and how far it still has to go.
Changing the Playing Field — Visual Editing in TYPO3 v14
Last weekend at Web Camp Venlo, developer Matthias Vogel demonstrated how the default Camino theme supports visual editing in TYPO3 v14. I believe this is a quantum leap for our CMS, both in terms of usability and for its appeal to potential clients.
TYPO3-EXT-SA-2026-007: Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
It has been discovered that the extension "E-Mail MFA Provider" (mfa_email) is vulnerable to Authentication Bypass.
TYPO3-EXT-SA-2026-006: Broken Access Control in extension "Redirect Tab" (redirect_tab)
It has been discovered that the extension "Redirect Tab" (redirect_tab) is vulnerable to Broken Access Control.