Roadmap for TYPO3 v14 — the High-Level Objectives and Strategic Goals
TYPO3 v14 LTS is scheduled for release at the end of April 2026. The Product Strategy Group has plans for ground-breaking changes to our favorite CMS. With your help, it will be the most significant release in years.
Read moreAnnual Report of the TYPO3 Documentation Team
The TYPO3 Documentation Team made significant strides in 2024, achieving groundbreaking advancements and key improvements. Let’s explore the accomplishments and contributions that defined this transformative year.
TYPO3 9.5.50, 10.4.49, and 11.5.43 ELTS Released
Still sticking to an older version of TYPO3? Today, 9.5.50, 10.4.49 and 11.5.43 have been released. Staying on top of maintenance updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!
TYPO3 13.4.4 and 12.4.26 maintenance releases published
The versions 13.4.4 and 12.4.26 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 9.5.49, 10.4.48, and 11.5.42 ELTS Released
Still sticking to an older version of TYPO3? Today, 9.5.49, 10.4.48 and 11.5.42 have been released. Staying on top of maintenance updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!
TYPO3-CORE-SA-2025-010: Cross-Site Request Forgery in DB Check Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-009: Cross-Site Request Forgery in Scheduler Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-008: Cross-Site Request Forgery in Indexed Search Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-007: Cross-Site Request Forgery in Form Framework Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.
TYPO3-CORE-SA-2025-006: Cross-Site Request Forgery in Extension Manager Module
It has been discovered that TYPO3 CMS is susceptible to cross-site request forgery.