Call for Community Budget Ideas (Q4/2025)
The TYPO3 Association has officially launched the fourth community budget process of 2025.
Read moreTYPO3-PSA-2025-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
TYPO3 13.4.17 and 12.4.36 maintenance releases published
The versions 13.4.17 and 12.4.36 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 13.4.16 and 12.4.35 maintenance releases published
The versions 13.4.16 and 12.4.35 of the TYPO3 Enterprise Content Management System have just been released.
Content Blocks — International Exchange and Major Feature Releases
TYPO3 Content Types Team Mid-Year Report: The first half of 2025 has been a vibrant and productive time for the Content Types Team. We’ve connected with the TYPO3 community at multiple camps—including TYPO3 Camp Central Germany, Switzerland, and Vienna—gathering valuable feedback and deepening engagement.
Coders' Corner: July 2025
Each month, we take the opportunity to celebrate TYPO3 contributors in our Developer Appreciation Day post. Please take a moment to share gratitude for their continued passion, commitment, and time they give to making TYPO3 CMS awesome.
The Documentation Team is Looking for Superheroes
Clear, reliable documentation empowers users, welcomes newcomers, and ensures long-term success. The TYPO3 Documentation Team is calling on community members to help improve and expand the docs. Every contribution, big or small, makes a difference.
Community Budget Report: Implementing Rector Rules for TYPO3 v13/v14
Simon Schaufelberger provides an update on his Community Budget Idea for Q2/2025.
TYPO3-EXT-SA-2025-010: Insecure Direct Object Reference in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Insecure Direct Object Reference.
TYPO3-EXT-SA-2025-009: Insecure Direct Object Reference in extension "powermail" (powermail)
It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.