TYPO3-CORE-SA-2026-002: Broken Access Control in Redirects Module
It has been discovered that TYPO3 CMS is susceptible to broken access control.
Read moreTYPO3-CORE-SA-2026-001: Broken Access Control in Edit Document Controller
It has been discovered that TYPO3 CMS is susceptible to broken access control.
Coder's Corner: December 2025
See the full recap of TYPO3’s November core contributions with 47 contributors, 148 reviews, bug fixes, features, and a big thank-you to our developers.
Enhanced Email Configuration — Approach and First Version
Email may be old, but it remains critical when reliability matters — and TYPO3 still lacks awareness of modern deliverability standards. This article outlines a first approach to central, validated sender configuration in TYPO3, making email setup safer and simpler for editors.
TYPO3-EXT-SA-2025-016: Vulnerability in bundled package in extension "Single Sign-on with SAML" (md_saml)
It has been discovered that the extension "Single Sign-on with SAML" (md_saml) bundles a vulnerable version of “onelogin/php-saml“ which is susceptible to Authentication Bypass.
Coder's Corner: November 2025
See the full recap of TYPO3’s November core contributions with 61 contributors, 297 reviews, bug fixes, features, and a big thank-you to our developers.
Why You Should Apply for TYPO3 Surfcamp 2026 – Ride the Waves & Code with the Community!
Discover why TYPO3 Surfcamp 2026 is the perfect blend of learning, surfing, and community growth. Happening April 11–18 in Fuerteventura. Free to attend—apply now before December 31, 2025.
Report from the TYPO3 Code Sprint in Geneva
27–31 October, TYPO3 contributors got together in Geneva, Switzerland, for a TYPO3 Code Sprint. It wasn’t just the Core Team — anyone interested in improving TYPO3 was welcome to join and this time, I had the pleasure of joining for the very first time.
TYPO3-EXT-SA-2025-015: Broken Authentication in extension "Modules" (modules)
It has been discovered that the extension "Modules" (modules) is susceptible to Broken Authentication.
TYPO3-EXT-SA-2025-014: Vulnerability in bundled package in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) bundles a vulnerable version of "phpoffice/phpspreadsheet", which is susceptible to Server-Side Request Forgery.