TYPO3-EXT-SA-2020-009: Cross-Site Scripting in extension "Faceted Search" (ke_search)
It has been discovered that the extension "Faceted Search" (ke_search) is susceptible to Cross-Site Scripting.
Read moreTYPO3 10.4.5 maintenance release published
The version 10.4.5 of the TYPO3 Enterprise Content Management System has just been released.
TYPO3 10.4.4 and 9.5.19 maintenance releases published
The versions 10.4.4 and 9.5.19 of the TYPO3 Enterprise Content Management System have just been released.
Structured Content Initiative—What happened in April? The survey results!
As promised in our last article, here’s our latest update from the TYPO3 Structured Content Initiative. Today we’re sharing results from our Survey of TYPO3 Editors.
TYPO3 10.4.3 and 9.5.18 maintenance releases published
The versions 10.4.3 and 9.5.18 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-CORE-SA-2020-006: Same-Origin Request Forgery to Backend User Interface
It has been discovered that TYPO3 CMS is vulnerable to same-origin request forgery.
TYPO3-CORE-SA-2020-005: Insecure Deserialization in Backend User Settings
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-EXT-SA-2020-008: Cross-Site Scripting in "SVG Sanitizer" (svg_sanitizer)
It has been discovered that the extension "SVG Sanitizer" (svg_sanitizer) is vulnerable to Cross-Site Scripting.
TYPO3-CORE-SA-2020-004: Class destructors causing side-effects when being unserialized
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
TYPO3-CORE-SA-2020-003: Cross-Site Scripting in Link Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.