TYPO3 News & Events Hub
What’s new & what’s comin’
Benefits of TYPO3 v10 LTS for Business Users
TYPO3 — Top 10 reasons to use the open source enterprise CMS Here’s how new features in TYPO3 v10 LTS improve user experience, performance, and security.
Read moreTYPO3 v6.2.49, 7.6.42 and 8.7.33 ELTS Released
Still sticking to an older version of TYPO3? There may be good reasons for doing so. Today, TYPO3 v6.2.49, 7.6.42 and 8.7.33 ELTS have been released. Staying on top of maintenance and security updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!
TYPO3-CORE-SA-2020-006: Same-Origin Request Forgery to Backend User Interface
It has been discovered that TYPO3 CMS is vulnerable to same-origin request forgery.
TYPO3-CORE-SA-2020-005: Insecure Deserialization in Backend User Settings
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-EXT-SA-2020-008: Cross-Site Scripting in "SVG Sanitizer" (svg_sanitizer)
It has been discovered that the extension "SVG Sanitizer" (svg_sanitizer) is vulnerable to Cross-Site Scripting.
TYPO3-CORE-SA-2020-004: Class destructors causing side-effects when being unserialized
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2020-003: Cross-Site Scripting in Link Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2020-007: Sensitive Data Exposure in extension "Job Fair" (jobfair)
It has been discovered that the extension "Job Fair" (jobfair) is susceptible to Sensitive Data Exposure.
TYPO3-CORE-SA-2020-002: Cross-Site Scripting in Form Engine
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2020-006: Broken Access Control in extension "gForum" (g_forum)
It has been discovered that the extension "gForum" (g_forum) is susceptible to Broken Access Control.