TYPO3-CORE-SA-2020-004: Class destructors causing side-effects when being unserialized
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
Read moreTYPO3-CORE-SA-2020-003: Cross-Site Scripting in Link Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2020-007: Sensitive Data Exposure in extension "Job Fair" (jobfair)
It has been discovered that the extension "Job Fair" (jobfair) is susceptible to Sensitive Data Exposure.
TYPO3-CORE-SA-2020-002: Cross-Site Scripting in Form Engine
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2020-006: Broken Access Control in extension "gForum" (g_forum)
It has been discovered that the extension "gForum" (g_forum) is susceptible to Broken Access Control.
TYPO3-CORE-SA-2020-001: Information Disclosure in Password Reset
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-EXT-SA-2020-005: Multiple vulnerabilities in extension "Direct Mail" (direct_mail)
It has been discovered that the extension "Direct Mail" (direct_mail) is susceptible to Denial of Service, Broken Access Control, Open Redirect and Information Disclosure.
TYPO3 10.4.2 and 9.5.17 security releases published
The versions 10.4.2 and 9.5.17 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-EXT-SA-2020-004: SQL Injection in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension "phpMyAdmin" (phpmyadmin) is susceptible to SQL Injection.
TYPO3 v10 Maintenance Release Schedule
TYPO3 v10 LTS receives a plannable release schedule for upcoming maintenance releases, as we did since TYPO3 v7 already. This makes it transparent for everybody in the TYPO3 Community to know when to expect a next bugfix and maintenance release.