<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by tag: Security</description>
        <language>en</language>
        <link>https://news.typo3.com/article/tag/security/blog.tag.xml</link>
        <lastBuildDate>Mon, 07 Sep 2026 12:21:34 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3 14.3.6 and 13.4.34 security releases published</title><link>https://news.typo3.com/article/typo3-1436-and-13434-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1436-and-13434-security-releases-published#comments</comments><pubDate>Tue, 11 Aug 2026 09:35:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1436-and-13434-security-releases-published</guid><description>The versions 14.3.6 and 13.4.34 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>TYPO3 14.3.5 and 13.4.33 security releases published</title><link>https://news.typo3.com/article/typo3-1435-and-13433-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1435-and-13433-security-releases-published#comments</comments><pubDate>Tue, 14 Jul 2026 14:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1435-and-13433-security-releases-published</guid><description>The versions 14.3.5 and 13.4.33 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>TYPO3 14.3.3 and 13.4.31 security releases published</title><link>https://news.typo3.com/article/typo3-1433-and-13431-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1433-and-13431-security-releases-published#comments</comments><pubDate>Tue, 09 Jun 2026 14:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1433-and-13431-security-releases-published</guid><description>The versions 14.3.3 and 13.4.31 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>Changes to the TYPO3 Bug Bounty Program</title><link>https://news.typo3.com/article/changes-to-the-typo3-bug-bounty-program</link><comments>https://news.typo3.com/article/changes-to-the-typo3-bug-bounty-program#comments</comments><pubDate>Tue, 19 May 2026 09:38:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/changes-to-the-typo3-bug-bounty-program</guid><description>Extension security reporting continues — financial rewards for extension findings will end on 31 May 2026.</description><enclosure
            length="150907"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/e/9/csm_Security_Blocker_listing_1400x933_LAY02_52ad5327dd.webp" /></item>


    
        
<item><title>TYPO3 14.0.2, 13.4.23 and 12.4.41 security releases published</title><link>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published</link><comments>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published#comments</comments><pubDate>Tue, 13 Jan 2026 13:00:00 +0100</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published</guid><description>The versions 14.0.2, 13.4.23 and 12.4.41 of the TYPO3 Enterprise Content Management System have just been released.</description><enclosure
            length="251750"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_2fec4ea8a8.webp" /></item>


    
        
<item><title>New ELTS Pricing for TYPO3 v12 – Effective April 2026</title><link>https://news.typo3.com/article/new-elts-pricing-v124</link><comments>https://news.typo3.com/article/new-elts-pricing-v124#comments</comments><pubDate>Thu, 02 Oct 2025 09:09:00 +0200</pubDate><dc:creator>Daniel Fau</dc:creator><guid>https://news.typo3.com/article/new-elts-pricing-v124</guid><description>New ELTS pricing for TYPO3 v12 starting April 2026, with membership discounts unchanged and early notice to support planning. No changes for v11 and v10.</description><enclosure
            length="492987"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/c/5/csm_header_ELTS_pricing_LAY03_62899e85fd.webp" /></item>


    
        
<item><title>Enhancing E-commerce Security: A Comprehensive Guide to CMS Threats and Solutions</title><link>https://news.typo3.com/article/enhancing-e-commerce-security-comprehensive-guide</link><comments>https://news.typo3.com/article/enhancing-e-commerce-security-comprehensive-guide#comments</comments><pubDate>Sun, 29 Sep 2024 09:31:00 +0200</pubDate><dc:creator>Panagiotis Semitekolos</dc:creator><guid>https://news.typo3.com/article/enhancing-e-commerce-security-comprehensive-guide</guid><description>How can the right CMS deliver e-commerce security? We review proven methods to keep e-commerce businesses safe, and what TYPO3 can do to support that goal.</description><enclosure
            length="301640"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/7/f/csm_Secure_E_Commerce_d06c3a372d.webp" /></item>


    
        
<item><title>How to Change the Entry Point in TYPO3 v13</title><link>https://news.typo3.com/article/how-to-change-the-entry-point-in-typo3-v13</link><comments>https://news.typo3.com/article/how-to-change-the-entry-point-in-typo3-v13#comments</comments><pubDate>Thu, 19 Sep 2024 09:00:00 +0200</pubDate><dc:creator>Tom Warwick</dc:creator><guid>https://news.typo3.com/article/how-to-change-the-entry-point-in-typo3-v13</guid><description>Find out how to change the backend entry point from /typo3 to anything you want, including subdomains with TYPO3 version 13.</description><enclosure
            length="338101"
            type="image/png"
            url="https://news.typo3.com/fileadmin/_processed_/7/1/csm_be_entry_bg_7f2af30c64.webp" /></item>


    
        
<item><title>TYPO3-EXT-SA-2024-001: Broken Access Control in extension &quot;Event management and registration&quot; (sf_event_mgt)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2024-001</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2024-001#comments</comments><pubDate>Tue, 13 Feb 2024 12:10:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2024-001</guid><description>It has been discovered that the extension &quot;Event management and registration&quot; (sf_event_mgt) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-011: Configuration Injection in extension &quot;Direct Mail&quot; (direct_mail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-011</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-011#comments</comments><pubDate>Wed, 13 Dec 2023 11:42:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-011</guid><description>It has been discovered that the extension &quot;Direct Mail&quot; (direct_mail) is susceptible to Configuration Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-010: Broken Access Control in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-010</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-010#comments</comments><pubDate>Wed, 13 Dec 2023 11:41:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-010</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-009: Insecure Direct Object Reference in extension &quot;Content Consent&quot; (content_consent)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-009</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-009#comments</comments><pubDate>Wed, 13 Dec 2023 11:40:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-009</guid><description>It has been discovered that the extension &quot;Content Consent&quot; (content_consent) is susceptible to Insecure Direct Object Reference.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-008: Broken Access Control in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-008</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-008#comments</comments><pubDate>Wed, 04 Oct 2023 11:40:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-008</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-007: Broken Access Control in extension &quot;hCaptcha for EXT:form&quot; (hcaptcha)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-007</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-007#comments</comments><pubDate>Thu, 17 Aug 2023 12:00:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-007</guid><description>It has been discovered that the extension &quot;hCaptcha for EXT:form&quot; (hcaptcha) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-006: Multiple vulnerabilities in extension &quot;Canto Extension&quot; (canto_extension)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-006</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-006#comments</comments><pubDate>Tue, 13 Jun 2023 10:02:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-006</guid><description>It has been discovered that the extension &quot;Canto Extension&quot; (canto_extension) is susceptible to Server Side Request Forgery and Remote Code Execution.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-005: SQL Injection in extension &quot;ipandlanguageredirect&quot; (ipandlanguageredirect)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-005</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-005#comments</comments><pubDate>Tue, 13 Jun 2023 10:01:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-005</guid><description>It has been discovered that the extension &quot;ipandlanguageredirect&quot; (ipandlanguageredirect) is susceptible to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-004: Cross-Site Scripting in extension &quot;Faceted Search&quot; (ke_search)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-004</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-004#comments</comments><pubDate>Tue, 13 Jun 2023 10:00:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-004</guid><description>It has been discovered that the extension &quot;Faceted Search&quot; (ke_search) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3 ELTS 8.7 - Year Four Is Now Live</title><link>https://news.typo3.com/article/typo3-elts-87-year-four-is-now-live</link><comments>https://news.typo3.com/article/typo3-elts-87-year-four-is-now-live#comments</comments><pubDate>Mon, 03 Apr 2023 08:00:00 +0200</pubDate><dc:creator>Jörg Ems</dc:creator><guid>https://news.typo3.com/article/typo3-elts-87-year-four-is-now-live</guid><description>Benefit from one more year of extended support for TYPO3 8.7. Increase your ROI and stay legally compliant.</description><enclosure
            length="138225"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/f/csm_eELTS87_header_blogpost_5983d005f2.webp" /></item>


    
        
<item><title>TYPO3-EXT-SA-2023-003: Cross-Site Scripting in extension &quot;Fluid Components&quot; (fluid_components)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-003</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-003#comments</comments><pubDate>Wed, 22 Mar 2023 12:40:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-003</guid><description>It has been discovered that the extension &quot;Fluid Components&quot; (fluid_components) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-002: Persisted Cross-Site Scripting in extension &quot;Forms Export&quot; (frp_form_answers)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-002</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-002#comments</comments><pubDate>Tue, 21 Feb 2023 11:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-002</guid><description>It has been discovered that the extension &quot;Forms Export&quot; (frp_form_answers) is susceptible to Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2023-001: Broken Access Control in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-001</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-001#comments</comments><pubDate>Tue, 31 Jan 2023 11:00:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2023-001</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>Extended ELTS for TYPO3 8.7—Pre-Orders Available Now</title><link>https://news.typo3.com/article/extended-elts-for-typo3-87-pre-orders-available-now</link><comments>https://news.typo3.com/article/extended-elts-for-typo3-87-pre-orders-available-now#comments</comments><pubDate>Sun, 01 Jan 2023 04:00:00 +0100</pubDate><dc:creator>Jörg Ems</dc:creator><guid>https://news.typo3.com/article/extended-elts-for-typo3-87-pre-orders-available-now</guid><description>Benefit from one more year of extended support for TYPO3 8.7. Increase your ROI and stay legally compliant.</description><enclosure
            length="138225"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/f/csm_eELTS87_header_blogpost_5983d005f2.webp" /></item>


    
        
<item><title>TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension &quot;Master-Quiz&quot; (fp_masterquiz)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-018</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-018#comments</comments><pubDate>Tue, 13 Dec 2022 12:32:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-018</guid><description>It has been discovered that the extension &quot;Master-Quiz&quot; (fp_masterquiz) is susceptible to Information Disclosure and Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2022-017: Multiple vulnerabilities in extension &quot;Newsletter subscriber management&quot; (fp_newsletter)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-017</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-017#comments</comments><pubDate>Tue, 13 Dec 2022 12:31:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-017</guid><description>It has been discovered that the extension &quot;Newsletter subscriber management&quot; (fp_newsletter) is susceptible to Information Disclosure and Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2022-016: Insufficient Session Expiration after Password Change in extension &quot;Change password for frontend users&quot; (fe_change_pwd) </title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-016</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-016#comments</comments><pubDate>Tue, 13 Dec 2022 12:30:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-016</guid><description>It has been discovered that the extension &quot;Change password for frontend users&quot; (fe_change_pwd) is susceptible to insufficient session expiration.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2022-015: Broken Access Control in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-015</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-015#comments</comments><pubDate>Wed, 02 Nov 2022 12:30:00 +0100</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-015</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>The Second Year Of ELTS 9.5 Starts Today</title><link>https://news.typo3.com/article/the-second-year-of-elts-95-starts-today</link><comments>https://news.typo3.com/article/the-second-year-of-elts-95-starts-today#comments</comments><pubDate>Sat, 01 Oct 2022 12:00:00 +0200</pubDate><dc:creator>Jörg Ems</dc:creator><guid>https://news.typo3.com/article/the-second-year-of-elts-95-starts-today</guid><description>ELTS keeps you up-to-date and legally compliant. While there is no one-size-fits-all for maintaining your website and keeping it safe, when a release moves into the ELTS phase, TYPO3 guarantees maintenance for an additional three-year period.</description><enclosure
            length="231631"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/8/e/csm_Header_ELTS_1920x564_5626a3047e.webp" /></item>


    
        
<item><title>TYPO3 ELTS 9.5 Will Soon Enter Its Second Year</title><link>https://news.typo3.com/article/typo3-elts-95-will-soon-enter-its-second-year</link><comments>https://news.typo3.com/article/typo3-elts-95-will-soon-enter-its-second-year#comments</comments><pubDate>Tue, 06 Sep 2022 12:00:00 +0200</pubDate><dc:creator>Jörg Ems</dc:creator><guid>https://news.typo3.com/article/typo3-elts-95-will-soon-enter-its-second-year</guid><description>If you need to maintain your TYPO3 9.5 installation(s) beyond September 30, 2022, you can benefit from ELTS 9.5 for up to two more years. The second year of ELTS 9.5 will start on October 1, 2022. </description><enclosure
            length="231631"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/8/e/csm_Header_ELTS_1920x564_5626a3047e.webp" /></item>


    
        
<item><title>Extended ELTS for TYPO3 8.7—it’s happening</title><link>https://news.typo3.com/article/extended-elts-for-typo3-87-its-happening</link><comments>https://news.typo3.com/article/extended-elts-for-typo3-87-its-happening#comments</comments><pubDate>Thu, 01 Sep 2022 10:31:06 +0200</pubDate><dc:creator>Jörg Ems</dc:creator><guid>https://news.typo3.com/article/extended-elts-for-typo3-87-its-happening</guid><description>At the request of our ELTS customers, we evaluated a continuation of ELTS 8.7 during August and have now decided to extend ELTS 8.7 one more year. Security and compatibility updates will be available for another year–until March 31, 2024!</description><enclosure
            length="138225"
            type="image/jpeg"
            url="https://news.typo3.com/fileadmin/_processed_/0/f/csm_eELTS87_header_blogpost_5983d005f2.webp" /></item>


    
        
<item><title>TYPO3-EXT-SA-2022-014: SQL Injection in extension &quot;LUX - TYPO3 Marketing Automation&quot; (lux)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-014</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-014#comments</comments><pubDate>Tue, 12 Jul 2022 10:00:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2022-014</guid><description>It has been discovered that the extension &quot;LUX - TYPO3 Marketing Automation&quot; (lux) is susceptible to SQL Injection.</description></item>


    



    </channel>
</rss>
