TYPO3 News & Events Hub
What’s New & What’s Coming
Stay up to date with the latest TYPO3 news and announcements by subscribing to our RSS feed.
Discontinuation of the Subversion Service at svn.typo3.org
Five years after the move of TYPO3 CMS to Git, the Subversion server svn.typo3.org will be shut down on May 1st, 2016.
Read moreKicking off TYPO3 v8 Development
The TYPO3 core team is officially starting the next development cycle. Sprint releases every 8-10 weeks along the way until TYPO3 8 LTS (Long Term Support) in April 2017 will ensure that new projects can possibly be set up with v8 already. A smooth upgrade path between the sprint releases will be provided.
TYPO3-EXT-SA-2016-006: Cross-Site Scripting in extension "Apache Solr for TYPO3" (solr)
It has been discovered that the extension "Apache Solr for TYPO3" (solr) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2016-005: Cross-Site Scripting in extension "Extension Kickstarter" (kickstarter)
It has been discovered that the extension "Extension Kickstarter" (kickstarter) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2016-004: Multiple vulnerabilities in extension "Fe user statistic" (festat)
It has been discovered that the extension "Fe user statistic" (festat) is susceptible to Cross-Site Scripting, Insecure Unserialize and Information Disclosure.
TYPO3-EXT-SA-2016-003: Cross-Site Scripting in extension "Google Sitemap" (enter_new_weeaar_googlesitemap)
It has been discovered that the extension "Google Sitemap" (enter_new_weeaar_googlesitemap) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2016-002: Cross-Site Scripting in extension "List frontend users" (listfeusers)
It has been discovered that the extension "List frontend users" (listfeusers) is susceptible to Cross-Site Scripting.
TYPO3-EXT-SA-2016-001: Information Disclosure in extension "UTOPIA" (ics_utopia)
It has been discovered that the extension "UTOPIA" (ics_utopia) is susceptible to Information Disclosure.
Farewell Carsten
Thursday, 25th of February 2016, Carsten Bleicker passed away
TYPO3-CORE-SA-2016-008: Denial of Service attack possibility in TYPO3 component Indexed Search
It has been discovered, that TYPO3 is susceptible to a Denial of Service attack.