TYPO3-EXT-SA-2021-008: Sensitive Information Disclosure in “Extbase Yaml Routes” (routes)
It has been discovered that the extension “Extbase Yaml Routes” (routes) is susceptible to Sensitive Information Disclosure.
Read moreTYPO3-CORE-SA-2021-013: Cross-Site Scripting via Rich-Text Content
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3 11.3.2, 10.4.19, 9.5.29, 8.7.42, 7.6.53 security releases published
The versions 11.3.2, 10.4.19, 9.5.29, 8.7.42, 7.6.53 of the TYPO3 Enterprise Content Management System have just been released.
July 2021: Developer Appreciation Day (DAD)
Each month, we take the opportunity to celebrate contributors in our Developer Appreciation Day post. Please take a moment to share gratitude for their continued passion, commitment, and time they give to making TYPO3 CMS awesome.
Documentation Restructuring—Status Update
We are pleased to announce that the first stage of the documentation restructuring process has been completed. The documentation homepage and the global menu changes were published last week and contain a new layout for the homepage and a restructured menu.
TYPO3 11.3.1, 10.4.18, 9.5.28, 8.7.41, 7.6.52 security releases published
The versions 11.3.1, 10.4.18, 9.5.28, 8.7.41, 7.6.52 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-PSA-2021-002: CSV Code Injection
It has been discovered that the TYPO3 extensions offering a CSV export might create CSV files that can contain formulas executed in external applications.
TYPO3-PSA-2021-001: Sensitive links in search results of TYPO3 extension indexed_search
It has been discovered that the TYPO3 extension “Indexed Search” may index sensitive links under certain conditions.
TYPO3-CORE-SA-2021-012: Information Disclosure in User Authentication
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2021-011: Cross-Site Scripting in Backend Grid View
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.