TYPO3-EXT-SA-2021-017: Multiple vulnerabilities in extension "pixx.io integration for TYPO3 (DAM)" (pixxio)
It has been discovered that the extension"pixx.io integration for TYPO3 (DAM)" (pixxio) is susceptible to Server-side request forgery, Remote Code Execution, Broken Access Control and vulnerable 3rd Party Components.
Read moreTYPO3-EXT-SA-2021-016: Denial of Service in extension "Code Highlight" (codehighlight)
It has been discovered that the extension "Code Highlight" (codehighlight) is susceptible to Denial of Service.
TYPO3-EXT-SA-2021-015: Cross-Site Scripting in extension "Google for Jobs" (google_for_jobs)
It has been discovered that the extension"Google for Jobs" (google_for_jobs) is susceptible to Cross-Site Scripting.
TYPO3 v11 Maintenance Release Schedule
TYPO3 v11 LTS was released in early October 2021, and it will have a predictable release plan for upcoming maintenance releases, as we have done since TYPO3 v7. It’s a transparent schedule so everybody in the TYPO3 Community can know when to expect the next bug-fix and maintenance release.
TYPO3 11.5.2 maintenance release published
The version 11.5.2 of the TYPO3 Enterprise Content Management System has just been released.
October 2021: Developer Appreciation Day (DAD)
Each month, we take the opportunity to celebrate contributors in our Developer Appreciation Day post. Please take a moment to share gratitude for their continued passion, commitment, and time they give to making TYPO3 CMS awesome.
Don’t Use Unsupported Software
Operating supported software protects your infrastructure but more importantly, it is part of your responsibility to protect the data of your customers.
Extension Award—Nomination
In a previous typo3.org news post, the TYPO3 Extension Award for best documentation was introduced. We would now like to inform you about the next steps. The winners of the award will receive prizes up to €1000.
TYPO3 11.5.1 maintenance release published
The version 11.5.1 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3-CORE-SA-2021-015: HTTP Host Header Injection in Request Handling
It has been discovered that TYPO3 CMS is vulnerable to HTTP header injection.