TYPO3-PSA-2019-003: Cross-Site Scripting in Flash component (ELTS)
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
Read moreTYPO3-PSA-2018-002: Web Resource Restrictions
It has been discovered that development related information can be retrieved by regular HTTP GET requests on NGINX web server environments missing strict access restriction settings.
TYPO3-PSA-2018-001: By-passing Protection of PharStreamWrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in PharStreamWrapper component.
TYPO3-PSA-2017-001: Privilege Escalation in Extension Repository (TER)
It has been discovered that the TYPO3 Extension Repository (TER) is vulnerable to privilege escalation.
TYPO3-PSA-2016-002: Important Security-Bulletin Pre-Announcement
TYPO3 releases containing a fix for a critical vulnerability will be published Tuesday 24th of May at about 10:00 a.m. CEST (08:00 a.m. GMT).
TYPO3-PSA-2016-001: Critical vulnerabilities in ImageMagick
Multiple vulnerabilities in ImageMagick have been discovered, Remote Code Execution being one of them.
TYPO3-PSA-2015-001: Important Security-Bulletin Pre-Announcement
A TYPO3 4.5.40 release containing a security fix will be published the day after tomorrow, Thursday 19th of February at about 10:00 am CET.
TYPO3-PSA-2014-001: Cross-Site Request Forgery Protection in TYPO3 CMS 6.2
TYPO3 CMS 6.2 will get CSRF Protection throughout all modules and parts that manipulate data.