TYPO3 News & Events Hub
What’s new & what’s comin’
Hat Tip to TYPO3 Coders - December 2017
Happy New Year to all of you! With 2018 now underway, we’d like to take the opportunity to thank all of the people who contributed to the TYPO3 core in December. Your engagement to the project is greatly appreciated and deserves special attention. Here's to you!
Read moreAnnouncing Selected Budget Ideas for 2018
The EAB has made a strategic selection of 9 topics to pursue from a pool of 17 submitted budget ideas.
TYPO3 CMS Website Maintenance
Avoid unnecessary website headaches by planning ahead. A website maintenance plan is the most reliable method to keep your website up to date and safe. Here are 6 tips to stay ahead of the curve.
Want to Contribute to TYPO3 CMS? Welcome!
Being open source software, TYPO3 relies on helping hands who are doing their bit to maintain the high-quality CMS. Fortunately, there are a lot of them, as last month’s numbers have shown. Are you interested in contributing to the TYPO3 project, too? Learn how you can get active and become a part of the TYPO3 community. Welcome!
TYPO3-EXT-SA-2017-020: Cross Site-Scripting in extension "Caretaker" (caretaker)
It has been discovered that the extension "Caretaker" (caretaker) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2017-019: Multiple vulnerabilities in extension "JobControl" (dmmjobcontrol)
It has been discovered that the extension "JobControl" (dmmjobcontrol) is susceptible to SQL Injection and Cross Site-Scripting.
TYPO3-EXT-SA-2017-018: Multiple vulnerabilities in extension "DRC News Comment" (news_comment)
It has been discovered that the extension "DRC News Comment" (news_comment) is susceptible to Arbitrary Code Execution and Cross Site-Scripting.
TYPO3-EXT-SA-2017-017: Authentication Bypass in extension "Frontend User Registration" (sf_register)
It has been discovered that the extension "Frontend User Registration" (sf_register) is vulnerable to Authentication Bypass.
TYPO3-EXT-SA-2017-016: SQL Injection in extension "Download Center" (pits_downloadcenter)
It has been discovered that the extension "Download Center" (pits_downloadcenter) is susceptible to SQL Injection.
TYPO3-EXT-SA-2017-015: Cross Site-Scripting in extension "Smallads" (ke_smallads)
It has been discovered that the extension "Smallads" (ke_smallads) is susceptible to Cross-Site Scripting.