TYPO3-EXT-SA-2019-001: Multiple vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension "phpMyAdmin" (phpmyadmin) is susceptible to Cross-Site Scripting, CSRF, File Inclusion and Remote Code Execution.
Read moreTYPO3-PSA-2019-001: Possible Arbitrary Code Execution in CommandUtility API
It has been discovered that TYPO3 CMS can be vulnerable to arbitrary code execution.
TYPO3-PSA-2019-002: Username and Email Address Enumeration
It has been discovered, that usernames and email addresses may be enumerated with brute-force techniques, when using validators in order to ensure a unique username or email address.
TYPO3-PSA-2019-003: Cross-Site Scripting in Flash component (ELTS)
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3 Developer Days 2019: Save the Date!
TYPO3 v9.5.3 LTS and v8.7.22 LTS released
The TYPO3 Community announces versions 9.5.3 LTS and 8.7.22 LTS of the TYPO3 Enterprise Content Management System.
TYPO3 9.5.2, 8.7.21 and 7.6.32 security releases published
The TYPO3 Community announces the versions 9.5.2 LTS, 8.7.21 LTS and 7.6.32 LTS of the TYPO3 Enterprise Content Management System.
TYPO3-CORE-SA-2018-012: Denial of Service in Frontend Record Registration
It has been discovered, that TYPO3 CMS is vulnerable to denial of service.
TYPO3-CORE-SA-2018-011: Denial of Service in Online Media Asset Handling
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2018-010: Information Disclosure in Install Tool
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.