TYPO3 News & Events Hub
What’s New & What’s Coming
Land ho! Feature Freeze Ahead!
Feature freeze ahead! This is a reminder to contributors that we have less than a month to bring in new features for TYPO3 v10 LTS (release scheduled in April 2020).
Read moreThe TYPO3 Marketing Team's 2020 Vision
TYPO3's Marketing Team lead, Luisa Faßbender, shares the teams' goals for 2020, as they get ready for a sprint to kick off the new decade.
December 2019: Developer Appreciation Day (DAD)
As 2020 begins, let’s take a moment to look back on last month’s achievements and - as usual - find a great deal of contributions to the TYPO3 project. Developer Appreciation Day (DAD) is our chance to give thanks to all the hardworking people who...
TYPO3 Developers—Get Certified!
The TYPO3 Association launched the official TYPO3 certification program more than a decade ago. Today, we offer four certification streams and one of them is the TYPO3 CMS Certified Developer (TCCD) that is the focus of this article. If you are a...
Mark Your Calendar! - TYPO3 Events in Q1 2020 and Beyond
Events and conferences are a great way to get together with like-minded people, gain knowledge and establish new business relationships. We compiled a list of TYPO3 events for Q1 2020 and beyond. Take out your calendars and make sure to mark these...
21 April 2020: TYPO3 v10 LTS Release and Party
The release date for TYPO3 v10 has been moved, and the new date is Tuesday, 21 April 2020. That’s the date of the TYPO3 Association’s General Assembly and the Grand Release Party at the TYPO3 Company office in Düsseldorf, Germany—and maybe at your...
SkillDisplay - The Final Erasmus+ Year
Happy New Year, everyone! The final year of the Erasmus+ Programme has already begun. The current article by SkillDisplay focuses on the future of Erasmus+ and the goals of the SkillDisplay GmbH.
Issues You Might Run Into When Upgrading TYPO3 Extensions
When considering to upgrade your TYPO3 installation, one of the bigger parts you need to take care of is the upgrade of all installed extensions. Some of them might be your own, others are public extensions.
TYPO3 v6.2.47 and 7.6.40 ELTS Released
Still sticking to an older version of TYPO3? There may be good reasons for doing so. Today, TYPO3 v6.2.47 and 7.6.40 ELTS have been released. Staying on top of maintenance and security updates should be a top priority - Gain peace of mind by opting...
CSRF in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Cross-Site-Request-Forgery (CSRF).
Privilege Escalation in extension "femanager direct mail subscription" (femanager_dmail_subscribe)
It has been discovered that the extension "femanager direct mail subscription" (femanager_dmail_subscribe) is susceptible to Privilege Escalation.
Cross Site Scripting in extension "File List" (file_list)
It has been discovered that the extension "File List" (file_list) is susceptible to Cross Site Scripting.
CSRF in extension "Change password for frontend users" (fe_change_pwd)
It has been discovered that the extension "Change password for frontend users" (fe_change_pwd) is susceptible to Cross-Site-Request-Forgery (CSRF).
Multiple vulnerabilities in extension "MKSamlAuth" (mksamlauth)
It has been discovered that the extension "MKSamlAuth" (mksamlauth) is susceptible to Broken Authentication and Authentication Bypass.
TYPO3 10.2.2, 9.5.13 and 8.7.30 security releases published
The TYPO3 Community announces the versions 10.2.2, 9.5.13 LTS and 8.7.30 LTS of the TYPO3 Enterprise Content Management System.
Insecure Deserialization in Query Generator & Query View
It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.
SQL Injection in low-level Query Generator
It has been discovered that TYPO3 CMS is vulnerable to SQL injection.
Directory Traversal on ZIP extraction
It has been discovered that TYPO3 CMS is vulnerable to directory traversal.
Cross-Site Scripting in Filelist Module
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
Cross-Site Scripting in Link Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting in Link Handling.