<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by category TYPO3 Extensions</description>
        <language>en</language>
        <link>https://news.typo3.com/article/category/security/typo3-extensions/blog.category.xml</link>
        <lastBuildDate>Tue, 28 Jul 2026 13:06:51 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3-EXT-SA-2026-013: Remote Code Execution in extension &quot;Content Element Selector&quot; (ceselector)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-013</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-013#comments</comments><pubDate>Tue, 19 May 2026 11:06:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-013</guid><description>It has been discovered that the extension &quot;Content Element Selector&quot; (ceselector) is vulnerable to Remote Code Execution.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-012: SQL Injection in extension &quot;Address List&quot; (tt_address)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-012</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-012#comments</comments><pubDate>Tue, 19 May 2026 11:05:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-012</guid><description>It has been discovered that the extension &quot;Address List&quot; (tt_address) is vulnerable to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-011: Multiple vulnerabilities in extension &quot;Faceted Search&quot; (ke_search)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-011</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-011#comments</comments><pubDate>Tue, 19 May 2026 11:03:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-011</guid><description>It has been discovered that the extension &quot;Faceted Search&quot; (ke_search) is vulnerable to XML External Entity injection, Path Traversal and Information Disclosure.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-010: SQL Injection in extension &quot;News system&quot; (news)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-010</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-010#comments</comments><pubDate>Tue, 19 May 2026 11:02:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-010</guid><description>It has been discovered that the extension &quot;News system&quot; (news) is vulnerable to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-009: Broken Access Control in extension &quot;Frontend User Registration&quot; (sf_register)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-009</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-009#comments</comments><pubDate>Tue, 19 May 2026 11:01:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-009</guid><description>It has been discovered that the extension &quot;Frontend User Registration&quot; (sf_register) is vulnerable to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-008: Remote Code Execution in extension &quot;Site Crawler&quot; (crawler)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-008</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-008#comments</comments><pubDate>Tue, 19 May 2026 11:00:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-008</guid><description>It has been discovered that the extension &quot;Site Crawler&quot; (crawler) is vulnerable to Remote Code Execution.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-007: Authentication Bypass in extension &quot;E-Mail MFA Provider&quot; (mfa_email)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-007</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-007#comments</comments><pubDate>Tue, 17 Mar 2026 10:02:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-007</guid><description>It has been discovered that the extension &quot;E-Mail MFA Provider&quot; (mfa_email) is vulnerable to Authentication Bypass.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-006: Broken Access Control in extension &quot;Redirect Tab&quot; (redirect_tab)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-006</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-006#comments</comments><pubDate>Tue, 17 Mar 2026 10:01:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-006</guid><description>It has been discovered that the extension &quot;Redirect Tab&quot; (redirect_tab) is vulnerable to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-005: Insecure Deserialization in extension &quot;Mailqueue&quot; (mailqueue)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-005</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-005#comments</comments><pubDate>Tue, 17 Mar 2026 10:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-005</guid><description>It has been discovered that the extension &quot;Mailqueue&quot; (mailqueue) is vulnerable to insecure deserialization.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-004: Vulnerability in bundled package in extension &quot;Amazon AWS SDK&quot; (aws)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-004</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-004#comments</comments><pubDate>Tue, 20 Jan 2026 08:33:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-004</guid><description>It has been discovered that the extension &quot;Amazon AWS SDK&quot; (aws) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-003: Vulnerability in bundled package in extension &quot;Amazon Web Services (AWS) Toolbox&quot; (aws_tools)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-003</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-003#comments</comments><pubDate>Tue, 20 Jan 2026 08:32:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-003</guid><description>It has been discovered that the extension &quot;Amazon Web Services (AWS) Toolbox&quot; (aws_tools) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-002: Vulnerability in bundled package in extension &quot;AWS SDK for PHP&quot; (aws_sdk_php)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-002</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-002#comments</comments><pubDate>Tue, 20 Jan 2026 08:31:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-002</guid><description>It has been discovered that the extension &quot;AWS SDK for PHP&quot; (aws_sdk_php) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-001: Insecure Deserialization in extension &quot;Mailqueue&quot; (mailqueue)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-001</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-001#comments</comments><pubDate>Tue, 20 Jan 2026 08:30:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-001</guid><description>It has been discovered that the extension &quot;Mailqueue&quot; (mailqueue) is vulnerable to insecure deserialization.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-016: Vulnerability in bundled package in extension &quot;Single Sign-on with SAML&quot; (md_saml)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-016</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-016#comments</comments><pubDate>Wed, 17 Dec 2025 10:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-016</guid><description>It has been discovered that the extension &quot;Single Sign-on with SAML&quot; (md_saml) bundles a vulnerable version of “onelogin/php-saml“ which is susceptible to Authentication Bypass.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-015: Broken Authentication in extension &quot;Modules&quot; (modules)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-015</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-015#comments</comments><pubDate>Wed, 12 Nov 2025 11:31:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-015</guid><description>It has been discovered that the extension &quot;Modules&quot; (modules) is susceptible to Broken Authentication.
</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-014: Vulnerability in bundled package in extension &quot;Forms Export&quot; (frp_form_answers)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-014</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-014#comments</comments><pubDate>Wed, 12 Nov 2025 11:30:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-014</guid><description>It has been discovered that the extension &quot;Forms Export&quot; (frp_form_answers) bundles a vulnerable version of &quot;phpoffice/phpspreadsheet&quot;, which is susceptible to Server-Side Request Forgery.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-013: Vulnerability in bundled package in extension &quot;Base Excel&quot; (base_excel)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-013</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-013#comments</comments><pubDate>Tue, 16 Sep 2025 10:31:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-013</guid><description>It has been discovered that the extension &quot;Base Excel&quot; (base_excel) bundles a vulnerable version of “phpoffice/phpspreadsheet“ which is susceptible to Server-Side Request Forgery.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-012: Cross-Site Scripting in extension &quot;Form to Database&quot; (form_to_database)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-012</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-012#comments</comments><pubDate>Tue, 16 Sep 2025 10:30:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-012</guid><description>It has been discovered that the extension &quot;Form to Database&quot; (form_to_database) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-011: Command Injection in extension &quot;TYPO3 Backup Plus&quot; (ns_backup)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-011</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-011#comments</comments><pubDate>Tue, 02 Sep 2025 10:30:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-011</guid><description>It has been discovered that the extension &quot;TYPO3 Backup Plus&quot; (ns_backup) is susceptible to Command Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-010: Insecure Direct Object Reference in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-010</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-010#comments</comments><pubDate>Tue, 22 Jul 2025 11:04:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-010</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-009: Insecure Direct Object Reference in extension &quot;powermail&quot; (powermail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-009</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-009#comments</comments><pubDate>Tue, 22 Jul 2025 11:02:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-009</guid><description>It has been discovered that the extension &quot;powermail&quot; (powermail) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-008: Multiple vulnerabilities in extension &quot;Front End User Registration&quot; (sr_feuser_register)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-008</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-008#comments</comments><pubDate>Tue, 20 May 2025 12:04:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-008</guid><description>It has been discovered that the extension &quot;Front End User Registration&quot; (sr_feuser_register) is susceptible to Remote Code Execution and Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-007: Multiple vulnerabilities in extension &quot;Backup Plus&quot; (ns_backup)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-007</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-007#comments</comments><pubDate>Tue, 20 May 2025 12:03:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-007</guid><description>It has been discovered that the extension &quot;Backup Plus&quot; (ns_backup) is susceptible to Command Injection, Predictable Resource Location and Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-006: Insecure Direct Object Reference in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-006</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-006#comments</comments><pubDate>Tue, 20 May 2025 12:02:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-006</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-005: Cross-Site Scripting in extension &quot;[clickstorm] SEO&quot; (cs_seo)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-005</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-005#comments</comments><pubDate>Tue, 20 May 2025 12:01:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-005</guid><description>It has been discovered that the extension &quot;[clickstorm] SEO&quot; (cs_seo) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-004: Insecure Direct Object Reference in extension &quot;Download manager&quot; (reint_downloadmanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-004</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-004#comments</comments><pubDate>Tue, 20 May 2025 12:00:00 +0200</pubDate><dc:creator>Marcus Krause</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-004</guid><description>It has been discovered that the extension &quot;Download manager&quot; (reint_downloadmanager) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-003: Multiple vulnerabilities in extension “[clickstorm] SEO” (cs_seo)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-003</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-003#comments</comments><pubDate>Tue, 18 Mar 2025 10:01:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-003</guid><description>It has been discovered that the extension &quot;[clickstorm] SEO&quot; (cs_seo) is susceptible to Cross-Site Scripting and Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-002: Cross-Site Scripting in extension “Additional TCA” (additional_tca)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-002</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-002#comments</comments><pubDate>Tue, 18 Mar 2025 10:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-002</guid><description>It has been discovered that the extension “Additional TCA” (additional_tca) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2025-001: Account Takeover in extension &quot;OpenID Connect Authentication&quot; (oidc)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-001</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-001#comments</comments><pubDate>Tue, 28 Jan 2025 14:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2025-001</guid><description>It has been discovered that the extension &quot;OpenID Connect Authentication&quot; (oidc) is susceptible to Account Takeover.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2024-007: Insecure Direct Object Reference in extension &quot;powermail&quot; (powermail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2024-007</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2024-007#comments</comments><pubDate>Tue, 17 Sep 2024 10:20:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2024-007</guid><description>It has been discovered that the extension &quot;powermail&quot; (powermail) is susceptible to Insecure Direct Object Reference.</description></item>


    



    </channel>
</rss>
