Coders' Corner: September 2025
Each month, we celebrate TYPO3 contributors in our Developer Appreciation Day post. Please take a moment to share gratitude for their continued passion and time.
Read moreContribute to Step‑by‑Step Guides — a New Way to Learn TYPO3 Hands‑On
Step‑by‑Step Guides are hands-on tutorials focused on completing a single, practical task from start to finish. Here’s what they are, how they differ from traditional documentation, and why they can be a go-to resource when learning or contributing to TYPO3.
TYPO3-EXT-SA-2025-013: Vulnerability in bundled package in extension "Base Excel" (base_excel)
It has been discovered that the extension "Base Excel" (base_excel) bundles a vulnerable version of “phpoffice/phpspreadsheet“ which is susceptible to Server-Side Request Forgery.
TYPO3-EXT-SA-2025-012: Cross-Site Scripting in extension "Form to Database" (form_to_database)
It has been discovered that the extension "Form to Database" (form_to_database) is susceptible to Cross-Site Scripting.
TYPO3-CORE-SA-2025-023: Information Disclosure via CSV Download
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-022: Information Disclosure in Workspaces Module
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-021: Broken Access Control in Backend AJAX Routes
It has been discovered that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2025-020: Information Disclosure via File Abstraction Layer
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2025-019: Insufficient Entropy in Password Generation
It has been discovered that TYPO3 CMS is susceptible to insufficient entropy.
TYPO3-CORE-SA-2025-018: Denial of Service in TYPO3 Bookmark Toolbar
It has been discovered that TYPO3 CMS is susceptible to denial of service.