TYPO3-EXT-SA-2026-017: Path Traversal in extension "Mask" (mask)
It has been discovered that the extension "Mask" (mask) is vulnerable to Path Traversal.
Read moreTYPO3-EXT-SA-2026-016: Information Disclosure in extension "Modules" (modules)
It has been discovered that the extension "Modules" (modules) is vulnerable to Information Disclosure.
TYPO3-EXT-SA-2026-015: Multiple Vulnerabilities in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
It has been discovered that the extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy) is vulnerable to Insufficient Session Expiration and Cleartext Transmission of Sensitive Information.
TYPO3-EXT-SA-2026-014: Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
It has been discovered that the extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) is vulnerable to Remote Code Execution.
TYPO3 Joins the PHP Foundation as a Silver Sponsor
In June 2026, TYPO3 joined the PHP Foundation as a Silver Sponsor, supporting the long-term development of the language its CMS and ecosystem have relied on for more than two decades.
TYPO3-EXT-SA-2026-013: Remote Code Execution in extension "Content Element Selector" (ceselector)
It has been discovered that the extension "Content Element Selector" (ceselector) is vulnerable to Remote Code Execution.
TYPO3-EXT-SA-2026-012: SQL Injection in extension "Address List" (tt_address)
It has been discovered that the extension "Address List" (tt_address) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-011: Multiple vulnerabilities in extension "Faceted Search" (ke_search)
It has been discovered that the extension "Faceted Search" (ke_search) is vulnerable to XML External Entity injection, Path Traversal and Information Disclosure.
TYPO3-EXT-SA-2026-010: SQL Injection in extension "News system" (news)
It has been discovered that the extension "News system" (news) is vulnerable to SQL Injection.
TYPO3-EXT-SA-2026-009: Broken Access Control in extension "Frontend User Registration" (sf_register)
It has been discovered that the extension "Frontend User Registration" (sf_register) is vulnerable to Broken Access Control.