<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by category Public Service Announcement</description>
        <language>en</language>
        <link>https://news.typo3.com/article/category/security/public-service-announcement/blog.category.xml</link>
        <lastBuildDate>Tue, 28 Jul 2026 13:04:24 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3-PSA-2025-001: Sanitization bypass in SVG Sanitizer</title><link>https://news.typo3.com/security/advisory/typo3-psa-2025-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2025-001#comments</comments><pubDate>Thu, 14 Aug 2025 10:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2025-001</guid><description>Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.</description></item>


    
        
<item><title>TYPO3-PSA-2023-001: Important Security-Bulletin Pre-Announcement</title><link>https://news.typo3.com/security/advisory/typo3-psa-2023-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2023-001#comments</comments><pubDate>Mon, 06 Feb 2023 09:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2023-001</guid><description>The TYPO3 Security Team pre-announces an important security release.</description></item>


    
        
<item><title>TYPO3-PSA-2022-001: Sanitization bypass in SVG Sanitizer</title><link>https://news.typo3.com/security/advisory/typo3-psa-2022-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2022-001#comments</comments><pubDate>Tue, 22 Feb 2022 10:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2022-001</guid><description>Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.</description></item>


    
        
<item><title>TYPO3-PSA-2021-004: Statement on Recent log4j/log4shell Vulnerabilities (CVE-2021-44228)</title><link>https://news.typo3.com/security/advisory/typo3-psa-2021-004</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2021-004#comments</comments><pubDate>Thu, 16 Dec 2021 12:01:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2021-004</guid><description>Components of TYPO3 CMS are based on PHP and are therefore not directly affected by the recent log4j vulnerabilities. However, additional services used in web application scenarios may be affected.</description></item>


    
        
<item><title>TYPO3-PSA-2021-003: Mitigation of Cache Poisoning Caused by Untrusted URL Query Parameters</title><link>https://news.typo3.com/security/advisory/typo3-psa-2021-003</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2021-003#comments</comments><pubDate>Thu, 16 Dec 2021 12:00:00 +0100</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2021-003</guid><description>It has been discovered that TYPO3 CMS is susceptible to cache poisoning.
</description></item>


    
        
<item><title>TYPO3-PSA-2021-002: CSV Code Injection</title><link>https://news.typo3.com/security/advisory/typo3-psa-2021-002</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2021-002#comments</comments><pubDate>Tue, 20 Jul 2021 11:01:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2021-002</guid><description>It has been discovered that the TYPO3 extensions offering a CSV export might create CSV files that can contain formulas executed in external applications.</description></item>


    
        
<item><title>TYPO3-PSA-2021-001: Sensitive links in search results of TYPO3 extension indexed_search</title><link>https://news.typo3.com/security/advisory/typo3-psa-2021-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2021-001#comments</comments><pubDate>Tue, 20 Jul 2021 11:00:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2021-001</guid><description>It has been discovered that the TYPO3 extension “Indexed Search” may index sensitive links under certain conditions.</description></item>


    
        
<item><title>TYPO3-PSA-2020-003: Mitigation of Cross-Site Scripting Vulnerabilities in File Upload Handling</title><link>https://news.typo3.com/security/advisory/typo3-psa-2020-003</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2020-003#comments</comments><pubDate>Tue, 17 Nov 2020 11:11:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2020-003</guid><description>Repeating and refining public service announcement TYPO3-PSA-2019-010.</description></item>


    
        
<item><title>TYPO3-PSA-2020-002: Protecting Install Tool with Sudo Mode</title><link>https://news.typo3.com/security/advisory/typo3-psa-2020-002</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2020-002#comments</comments><pubDate>Tue, 17 Nov 2020 11:10:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2020-002</guid><description>Accessing Install Tool via TYPO3 Backend requires password verification - known as Sudo Mode.</description></item>


    
        
<item><title>TYPO3-PSA-2020-001: Critical vulnerability in legacy versions of TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-psa-2020-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2020-001#comments</comments><pubDate>Tue, 28 Jul 2020 11:00:00 +0200</pubDate><dc:creator>[No title]</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2020-001</guid><description>It has been discovered that TYPO3 CMS is susceptible to sensitive information disclosure in previous TYPO3 versions which are not maintained by the community anymore.</description></item>


    
        
<item><title>TYPO3-PSA-2019-011: Possible Insecure Deserialization in Extbase Request Handling</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-011</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-011#comments</comments><pubDate>Tue, 17 Dec 2019 09:44:28 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-011</guid><description>It has been discovered that TYPO3 CMS can be vulnerable to insecure deserialization.</description></item>


    
        
<item><title>TYPO3-PSA-2019-010: Cross-Site Scripting Vulnerabilities in File Upload Handling</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-010</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-010#comments</comments><pubDate>Tue, 17 Dec 2019 09:44:28 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-010</guid><description>It has been discovered that TYPO3 is susceptible to cross-site scripting.</description></item>


    
        
<item><title>TYPO3-PSA-2019-009: Truncated passwords during authentication process on typo3.org services</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-009</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-009#comments</comments><pubDate>Wed, 30 Oct 2019 20:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-009</guid><description>It has been discovered that passwords were truncated during authentication process on typo3.org services.</description></item>


    
        
<item><title>TYPO3-PSA-2019-008: By-passing protection of Phar Stream Wrapper Interceptor</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-008</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-008#comments</comments><pubDate>Wed, 08 May 2019 09:25:38 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-008</guid><description>It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.</description></item>


    
        
<item><title>TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-007</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-007#comments</comments><pubDate>Wed, 08 May 2019 09:04:48 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-007</guid><description>It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.</description></item>


    
        
<item><title>TYPO3-PSA-2019-006: Security Misconfiguration since TYPO3 9.4.0</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-006</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-006#comments</comments><pubDate>Tue, 07 May 2019 10:35:34 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-006</guid><description>It has been discovered that TYPO3 is susceptible to security misconfiguration.</description></item>


    
        
<item><title>TYPO3-PSA-2019-005: Cross-Site Scripting in Bootstrap CSS toolkit before 3.4.1 and 4.3.0</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-005</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-005#comments</comments><pubDate>Tue, 07 May 2019 10:32:30 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-005</guid><description>It has been discovered that 3rd party library Bootstrap CSS toolkit bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.</description></item>


    
        
<item><title>TYPO3-PSA-2019-004: Cross-Site Scripting in jQuery before 3.4.0</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-004</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-004#comments</comments><pubDate>Tue, 07 May 2019 10:25:22 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-004</guid><description>It has been discovered that 3rd party library jQuery bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.</description></item>


    
        
<item><title>TYPO3-PSA-2019-001: Possible Arbitrary Code Execution in CommandUtility API</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-001#comments</comments><pubDate>Tue, 22 Jan 2019 10:00:00 +0100</pubDate><dc:creator>[No title]</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-001</guid><description>It has been discovered that TYPO3 CMS can be vulnerable to arbitrary code execution.</description></item>


    
        
<item><title>TYPO3-PSA-2019-002: Username and Email Address Enumeration</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-002</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-002#comments</comments><pubDate>Tue, 22 Jan 2019 10:00:00 +0100</pubDate><dc:creator>[No title]</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-002</guid><description>It has been discovered, that usernames and email addresses may be enumerated with brute-force techniques, when using validators in order to ensure a unique username or email address.</description></item>


    
        
<item><title>TYPO3-PSA-2019-003: Cross-Site Scripting in Flash component (ELTS)</title><link>https://news.typo3.com/security/advisory/typo3-psa-2019-003</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2019-003#comments</comments><pubDate>Tue, 22 Jan 2019 10:00:00 +0100</pubDate><dc:creator>[No title]</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2019-003</guid><description>It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>TYPO3-PSA-2018-002: Web Resource Restrictions</title><link>https://news.typo3.com/security/advisory/typo3-psa-2018-002</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2018-002#comments</comments><pubDate>Tue, 20 Nov 2018 11:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2018-002</guid><description>It has been discovered that development related information can be retrieved by regular HTTP GET requests on NGINX web server environments missing strict access restriction settings.</description></item>


    
        
<item><title>TYPO3-PSA-2018-001: By-passing Protection of PharStreamWrapper Interceptor</title><link>https://news.typo3.com/security/advisory/typo3-psa-2018-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2018-001#comments</comments><pubDate>Thu, 18 Oct 2018 10:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2018-001</guid><description>It has been discovered that the protection against insecure deserialization can be by-passed in PharStreamWrapper component.</description></item>


    
        
<item><title>TYPO3-PSA-2017-001: Privilege Escalation in Extension Repository (TER)</title><link>https://news.typo3.com/security/advisory/typo3-psa-2017-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2017-001#comments</comments><pubDate>Wed, 06 Sep 2017 12:00:00 +0200</pubDate><dc:creator>Thomas Löffler</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2017-001</guid><description>It has been discovered that the TYPO3 Extension Repository (TER) is vulnerable to privilege escalation.</description></item>


    
        
<item><title>TYPO3-PSA-2016-002: Important Security-Bulletin Pre-Announcement</title><link>https://news.typo3.com/security/advisory/typo3-psa-2016-002</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2016-002#comments</comments><pubDate>Fri, 20 May 2016 11:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2016-002</guid><description>TYPO3 releases containing a fix for a critical vulnerability will be published Tuesday 24th of May at about 10:00 a.m. CEST (08:00 a.m. GMT).</description></item>


    
        
<item><title>TYPO3-PSA-2016-001: Critical vulnerabilities in ImageMagick</title><link>https://news.typo3.com/security/advisory/typo3-psa-2016-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2016-001#comments</comments><pubDate>Thu, 05 May 2016 13:00:00 +0200</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2016-001</guid><description>Multiple vulnerabilities in ImageMagick have been discovered, Remote Code Execution being one of them.</description></item>


    
        
<item><title>TYPO3-PSA-2015-001: Important Security-Bulletin Pre-Announcement</title><link>https://news.typo3.com/security/advisory/typo3-psa-2015-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2015-001#comments</comments><pubDate>Tue, 17 Feb 2015 12:30:00 +0100</pubDate><dc:creator>Helmut Hummel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2015-001</guid><description>A TYPO3 4.5.40 release containing a security fix will be published the day after tomorrow, 
Thursday 19th of February at about 10:00 am CET.
</description></item>


    
        
<item><title>TYPO3-PSA-2014-001: Cross-Site Request Forgery Protection in TYPO3 CMS 6.2</title><link>https://news.typo3.com/security/advisory/typo3-psa-2014-001</link><comments>https://news.typo3.com/security/advisory/typo3-psa-2014-001#comments</comments><pubDate>Tue, 28 Jan 2014 14:08:00 +0100</pubDate><dc:creator>[No title]</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-psa-2014-001</guid><description>TYPO3 CMS 6.2 will get CSRF Protection throughout all modules and parts that manipulate data.</description></item>


    



    </channel>
</rss>
