TYPO3-CORE-SA-2025-018: Denial of Service in TYPO3 Bookmark Toolbar
It has been discovered that TYPO3 CMS is susceptible to denial of service.
Read moreTYPO3-CORE-SA-2025-017: Open Redirect in TYPO3 CMS
It has been discovered that TYPO3 CMS is susceptible to open redirect.
TYPO3 13.4.18 and 12.4.37 security releases published
The versions 13.4.18 and 12.4.37 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3-EXT-SA-2025-011: Command Injection in extension "TYPO3 Backup Plus" (ns_backup)
It has been discovered that the extension "TYPO3 Backup Plus" (ns_backup) is susceptible to Command Injection.
Call for Community Budget Ideas (Q4/2025)
The TYPO3 Association has officially launched the fourth community budget process of 2025.
TYPO3-PSA-2025-001: Sanitization bypass in SVG Sanitizer
Third-party package enshrined/svg-sanitize, used by TYPO3 core packages, was susceptible to bypassing the sanitization strategy.
TYPO3 13.4.17 and 12.4.36 maintenance releases published
The versions 13.4.17 and 12.4.36 of the TYPO3 Enterprise Content Management System have just been released.
TYPO3 13.4.16 and 12.4.35 maintenance releases published
The versions 13.4.16 and 12.4.35 of the TYPO3 Enterprise Content Management System have just been released.
Content Blocks — International Exchange and Major Feature Releases
TYPO3 Content Types Team Mid-Year Report: The first half of 2025 has been a vibrant and productive time for the Content Types Team. We’ve connected with the TYPO3 community at multiple camps—including TYPO3 Camp Central Germany, Switzerland, and Vienna—gathering valuable feedback and deepening engagement.
Community Budget Report: Implementing Rector Rules for TYPO3 v13/v14
Simon Schaufelberger provides an update on his Community Budget Idea for Q2/2025.