TYPO3-CORE-SA-2021-004: Cross-Site Scripting in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
Read moreTYPO3-CORE-SA-2021-003: Broken Access Control in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to broken access control.
TYPO3-CORE-SA-2021-002: Unrestricted File Upload in Form Framework
It has been discovered that TYPO3 CMS is vulnerable to unrestricted file upload.
TYPO3-CORE-SA-2021-001: Open Redirection in Login Handling
It has been discovered that TYPO3 CMS is susceptible to open redirection.
TYPO3 11.1.1, 10.4.14, 9.5.25 security releases published
The versions 11.1.1, 10.4.14, 9.5.25, 8.7.40, 7.6.51, 6.2.57 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-EXT-SA-2021-003: Cross-Site Scripting in extension "Aimeos shop and e-commerce framework" (aimeos)
It has been discovered that the extension"Aimeos shop and e-commerce framework" (aimeos) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2021-002: Denial of Service in extension "Code Highlight" (codehighlight)
It has been discovered that the extension "Code Highlight" (codehighlight) is susceptible to Denial of Service.
TYPO3-EXT-SA-2021-001: SQL Injection in extension "VHS: Fluid ViewHelpers" (vhs)
It has been discovered that the extension "VHS: Fluid ViewHelpers" (vhs) is susceptible to SQL Injection.
We Want You as Core Merger in 2021
Every year we are re-evaluating the Core Mergers positions, and open up for new people to join the efforts of driving TYPO3 Core's development further. And 2021 could be your year to join?
February 2021: Developer Appreciation Day (DAD)
Each month, we take the opportunity to celebrate contributors in our Developer Appreciation Day post. Please take a moment to share gratitude for their continued passion, commitment, and time they give to making TYPO3 CMS awesome.