TYPO3-PSA-2025-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
Read moreTYPO3-PSA-2023-001: Important Security-Bulletin Pre-Announcement
The TYPO3 Security Team pre-announces an important security release.
TYPO3-PSA-2022-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
TYPO3-PSA-2021-004: Statement on Recent log4j/log4shell Vulnerabilities (CVE-2021-44228)
Components of TYPO3 CMS are based on PHP and are therefore not directly affected by the recent log4j vulnerabilities. However, additional services used in web application scenarios may be affected.
TYPO3-PSA-2021-003: Mitigation of Cache Poisoning Caused by Untrusted URL Query Parameters
It has been discovered that TYPO3 CMS is susceptible to cache poisoning.
TYPO3-PSA-2021-002: CSV Code Injection
It has been discovered that the TYPO3 extensions offering a CSV export might create CSV files that can contain formulas executed in external applications.
TYPO3-PSA-2021-001: Sensitive links in search results of TYPO3 extension indexed_search
It has been discovered that the TYPO3 extension “Indexed Search” may index sensitive links under certain conditions.
TYPO3-PSA-2020-003: Mitigation of Cross-Site Scripting Vulnerabilities in File Upload Handling
Repeating and refining public service announcement TYPO3-PSA-2019-010.
TYPO3-PSA-2020-002: Protecting Install Tool with Sudo Mode
Accessing Install Tool via TYPO3 Backend requires password verification - known as Sudo Mode.
TYPO3-PSA-2020-001: Critical vulnerability in legacy versions of TYPO3 CMS
It has been discovered that TYPO3 CMS is susceptible to sensitive information disclosure in previous TYPO3 versions which are not maintained by the community anymore.