TYPO3-EXT-SA-2022-005: Remote Code Execution in extension "Job portal" (psvneo_jobfair)
It has been discovered that the extension "Job portal" (psvneo_jobfair) is susceptible to Remote Code Execution.
Read moreTYPO3 11.5.9 and 10.4.27 maintenance releases published
The versions 11.5.9 and 10.4.27 of the TYPO3 Enterprise Content Management System have just been released.
Code the TYPO3 Core in 2022
Every year we are re-evaluating the Core development workflow, and open up for new people to join the efforts of driving TYPO3 Core's development further. Maybe 2022 could be your year to join?
TYPO3 11.5.8 and 10.4.26 maintenance releases published
The versions 11.5.8 and 10.4.26 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 11.5.7 and 10.4.25 maintenance releases published
The versions 11.5.7 and 10.4.25 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-PSA-2022-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
TYPO3-EXT-SA-2022-004: File Content Injection in extension "Hardcoded text to Locallang" (mqk_locallangtools)
It has been discovered that the extension "Hardcoded text to Locallang" (mqk_locallangtools) is susceptible to File Content Injection.
TYPO3-EXT-SA-2022-003: Insecure direct object reference in extension "Varnishcache" (varnishcache)
It has been discovered that the extension "Varnishcache" (varnishcache) is susceptible to Insecure direct object reference.
TYPO3-EXT-SA-2022-002: Cross-Site Scripting in extension "Bookdatabase" (extbookdatabase)
It has been discovered that the extension "Bookdatabase" (extbookdatabase) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2022-001: Server-side request forgery in extension "Kitodo.Presentation" (dlf)
It has been discovered that the extension "Kitodo.Presentation" (dlf) is susceptible to Server-side request forgery.