<?xml version="1.0" encoding="utf-8"?>


    <rss version="2.0"
         xmlns:content="http://purl.org/rss/1.0/modules/content/"
         xmlns:atom="http://www.w3.org/2005/Atom">
        <channel>
            <title>Official TYPO3 News</title>
            <link>https://news.typo3.com/</link>
            <description></description>
            <language>en-US</language>
            <copyright>TYPO3 News</copyright>
            <pubDate>Thu, 09 Apr 2026 16:04:04 +0200</pubDate>
            <lastBuildDate>Thu, 09 Apr 2026 16:04:04 +0200</lastBuildDate>
            <atom:link href="https://news.typo3.com/rss" rel="self" type="application/rss+xml" />
            <generator>TYPO3 EXT:news_events</generator>
            
                
                    <item>
                        <guid isPermaLink="false">post-1994</guid>
                        <pubDate>Wed, 08 Apr 2026 20:30:33 +0200</pubDate>
                        <title>Announcing a Third Election Round for the TYPO3 Association Board</title>
                        <link>https://news.typo3.com/article/announcing-a-third-election-round-for-the-typo3-association-board</link>
                        <description>Since none of the remaining candidates achieved 50% of the votes in the second round, members are asked to vote in a final round. If the necessary support is not reached, the election for the third position will be considered unsuccessful.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/7/7/csm_TYPO3_Board_and_BCC_Candidates_Checkmark_Question_With_Opacity_913c511f5d.webp" length="278538" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1993</guid>
                        <pubDate>Wed, 08 Apr 2026 10:42:22 +0200</pubDate>
                        <title>Vote Now! Budget 2026 Ideas for Round Two Have Been Published</title>
                        <link>https://news.typo3.com/article/vote-now-budget-2026-ideas-for-round-two-have-been-published</link>
                        <description>The call for community budget ideas for the second round of 2026 was successful: Seven Community and three Team ideas have made it to the poll. These ideas can now be discussed and TYPO3 Association members can cast their vote.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/TYPO3_Stock/Icon_Designs/TYPO3_Circles_Ballot_Check_Dollar.svg" length="5556" type="image/svg+xml"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1991</guid>
                        <pubDate>Tue, 07 Apr 2026 10:37:48 +0200</pubDate>
                        <title>This Month in TYPO3: March, 2026</title>
                        <link>https://news.typo3.com/article/this-month-in-typo3-march-2026</link>
                        <description>March went out with a bang. TYPO3 v14.2 shipped on the final day of the month, the Association elections saw an 18% surge in voter participation, and three extension security advisories landed mid-month. With v14 LTS queued for 21 April and the community calendar filling fast, the momentum heading into spring is undeniable.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/b/8/csm_This-Month-In-TYPO3-March-2026_83afe4d75f.webp" length="81736" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1989</guid>
                        <pubDate>Thu, 02 Apr 2026 00:00:00 +0200</pubDate>
                        <title>Improving Fluid Developer Experience with TYPO3 v14</title>
                        <link>https://news.typo3.com/article/improving-fluid-dx-with-typo3-v14</link>
                        <description>Simon Praetorius gives us an update on his Community Budget idea for improving the Fluid developer experience — and the first results are already landing in Fluid 5.2.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/e/7/csm_event_laptop_work_04_7ba759a880.webp" length="240962" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1982</guid>
                        <pubDate>Wed, 01 Apr 2026 06:03:42 +0200</pubDate>
                        <title>TYPO3 Contribution in Numbers: March 2026</title>
                        <link>https://news.typo3.com/article/typo3-contribution-in-numbers-march-2026</link>
                        <description>See the full recap of TYPO3&#039;s March core contributions with 66 contributors, 255 reviews, bug fixes, features, and a big thank-you to our developers.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/c/0/csm_DAD_listing_1400x933_LAY01__1__45cdadc4fa.webp" length="170804" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1974</guid>
                        <pubDate>Tue, 31 Mar 2026 07:08:00 +0200</pubDate>
                        <title>TYPO3 v14.2—Refined Where It Matters</title>
                        <link>https://news.typo3.com/article/typo3-v142-refined-where-it-matters</link>
                        <description>Today we proudly released TYPO3 version 14.2—and you won&#039;t be disappointed! You&#039;ll find new features, improvements, and optimizations in every corner of the system. Read on to learn more about what&#039;s new in the last sprint release before the v14 LTS launch in April 2026.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/3/0/csm_v14_2_Keyvisual_82f8cb5f2c.webp" length="69682" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1981</guid>
                        <pubDate>Tue, 31 Mar 2026 07:00:00 +0200</pubDate>
                        <title>Results of the 2026 TYPO3 Association Elections</title>
                        <link>https://news.typo3.com/article/results-of-the-2026-typo3-association-elections</link>
                        <description>When the election closed, more than 380 members had cast their votes. This is an 18% increase from 2025. Another voting round will take place to select the final board member.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/a/3/csm_TYPO3_Board_and_BCC_Candidates_Checkmark_Question_eaadb64dae.webp" length="330414" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1969</guid>
                        <pubDate>Thu, 26 Mar 2026 07:00:00 +0100</pubDate>
                        <title>How to Upgrade an Outdated TYPO3 Version: Our Step-by-Step Guide</title>
                        <link>https://news.typo3.com/article/how-to-upgrade-an-outdated-typo3-version-our-step-by-step-guide</link>
                        <description>Learn how to check if your TYPO3 version is outdated and choose the best way to upgrade your TYPO3 website.</description>
                        
                        
                        
                            
                                <category>Market &amp; Sell</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/7/4/csm_dont_panic_cf10ced46a.webp" length="381770" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1973</guid>
                        <pubDate>Wed, 25 Mar 2026 10:32:51 +0100</pubDate>
                        <title>TYPO3 and its Accessibility in the Backend — Changes from v6 to v14</title>
                        <link>https://news.typo3.com/article/typo3-and-its-accessibility-in-the-backend-changes-from-v6-to-v14</link>
                        <description>A look at how the TYPO3 community has tackled backend accessibility over the years — and what a dedicated sprint in 2025 revealed about how far it&#039;s come, and how far it still has to go.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/0/e/csm_accessibility_team_test_group_78b67221ba.webp" length="455612" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1964</guid>
                        <pubDate>Wed, 25 Mar 2026 09:05:00 +0100</pubDate>
                        <title>Extended Long-Term Support (ELTS) for TYPO3 v12: Presale starts 1 April 2026</title>
                        <link>https://news.typo3.com/article/elts-v12-presale</link>
                        <description>Prepare for the end of TYPO3 v12 LTS free support on 30 April 2026. Consider extending your current system&#039;s life with ELTS for critical security updates and bug fixes.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/7/d/csm_v12.4_listing_1400x933_LAY03_c523b9cc40.webp" length="38780" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1966</guid>
                        <pubDate>Tue, 24 Mar 2026 06:01:00 +0100</pubDate>
                        <title>Join the TYPO3 v14 LTS Launch Celebrations</title>
                        <link>https://news.typo3.com/article/join-the-typo3-v14-lts-launch-festivities</link>
                        <description>Join the TYPO3 community in marking the release of TYPO3 v14 LTS. The official release day is 21 April 2026, and we’re excited to highlight release parties happening across the ecosystem.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/9/6/csm_News_T3v14-Watchparty_Teaser_cbd01c1a4a.webp" length="74832" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1962</guid>
                        <pubDate>Tue, 17 Mar 2026 16:52:11 +0100</pubDate>
                        <title>Changing the Playing Field — Visual Editing in TYPO3 v14</title>
                        <link>https://news.typo3.com/article/visual-editing-in-typo3-v14</link>
                        <description>Last weekend at Web Camp Venlo, developer Matthias Vogel demonstrated how the default Camino theme supports visual editing in TYPO3 v14. I believe this is a quantum leap for our CMS, both in terms of usability and for its appeal to potential clients.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/0/2/csm_Visual_Editor_Vignette_7cc587d200.webp" length="100496" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2922</guid>
                        <pubDate>Tue, 17 Mar 2026 10:02:00 +0100</pubDate>
                        <title>Authentication Bypass in extension &quot;E-Mail MFA Provider&quot; (mfa_email)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-007</link>
                        <description>It has been discovered that the extension &quot;E-Mail MFA Provider&quot; (mfa_email) is vulnerable to Authentication Bypass.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: March 17, 2026</span><span>Updated: March 22, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/mfa_email" target="_blank" rel="noreferrer"><span>"E-Mail MFA Provider" (mfa_email)</span></a><span>Composer Package Name: ralffreit/mfa-email</span><span>Vulnerability Type: Authentication Bypass</span><span>Affected Versions: 2.0.0, 1.0.5 and below</span><span>Severity: High</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span></a><span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-4208" target="_blank" rel="noreferrer"><span>CVE-2026-4208</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/288.html" target="_blank" rel="noreferrer"><span>CWE-288</span></a><h3>Problem Description</h3>
<p>The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.<br><br>The vulnerability is only exploitable, when the “E-Mail MFA Provider” is not the default MFA provider and when at least one other MFA provider is available to the user.</p>
<h3>Solution</h3>
<p>Updated versions 2.0.1 and 1.0.7 are available from the TYPO3 extension manager, packagist and at</p>
<p><a href="https://extensions.typo3.org/extension/download/mfa_email/2.0.1/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/mfa_email/2.0.1/zip</a><br><a href="https://extensions.typo3.org/extension/download/mfa_email/1.0.7/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/mfa_email/1.0.7/zip</a></p>
<p>Users of the extension are advised to update the extension as soon as possible.</p>
<h3>Credits</h3>
<p>Thanks to Jan Holtkötter for reporting the vulnerability and to Ralf Freit for providing an updated version of the extension.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2921</guid>
                        <pubDate>Tue, 17 Mar 2026 10:01:00 +0100</pubDate>
                        <title>Broken Access Control in extension &quot;Redirect Tab&quot; (redirect_tab)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-006</link>
                        <description>It has been discovered that the extension &quot;Redirect Tab&quot; (redirect_tab) is vulnerable to Broken Access Control.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: March 17, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/redirect_tab" target="_blank" rel="noreferrer"><span>"Redirect Tab" (redirect_tab)</span></a><span>Composer Package Name: ayacoo/redirect-tab</span><span>Vulnerability Type: Broken Access Control</span><span>Affected Versions: 4.0.0 - 4.0.4, 3.0.0 - 3.1.6, 2.1.1 and below</span><span>Severity: Low</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</span></a><span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-4202" target="_blank" rel="noreferrer"><span>CVE-2026-4202</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noreferrer"><span>CWE-862</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/200.html" target="_blank" rel="noreferrer"><span>CWE-200</span></a><h3>Problem Description</h3>
<p>The extension fails to verify, if an authenticated user has permissions to access redirects resulting in exposure of redirect records when editing a page.</p>
<h3>Solution</h3>
<p>Updated versions 4.0.5, 3.1.7 and 2.1.2 are available from the TYPO3 extension manager, packagist and at</p>
<p><a href="https://extensions.typo3.org/extension/download/redirect_tab/4.0.5/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/redirect_tab/4.0.5/zip</a><br><a href="https://extensions.typo3.org/extension/download/redirect_tab/3.1.7/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/redirect_tab/3.1.7/zip</a><br><a href="https://extensions.typo3.org/extension/download/redirect_tab/2.1.2/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/redirect_tab/2.1.2/zip</a></p>
<p>Users of the extension are advised to update the extension as soon as possible.</p>
<h3>Credits</h3>
<p>Thanks to Guido Schmechel for reporting the vulnerability and for providing updated versions of the extension.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2920</guid>
                        <pubDate>Tue, 17 Mar 2026 10:00:00 +0100</pubDate>
                        <title>Insecure Deserialization in extension &quot;Mailqueue&quot; (mailqueue)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-005</link>
                        <description>It has been discovered that the extension &quot;Mailqueue&quot; (mailqueue) is vulnerable to insecure deserialization.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: March 17, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/mailqueue" target="_blank" rel="noreferrer"><span>"Mailqueue" (mailqueue)</span></a><span>Composer Package Name: cpsit/typo3-mailqueue</span><span>Vulnerability Type: Insecure Deserialization</span><span>Affected Versions: 0.5.0 - 0.5.1, 0.4.4 and below</span><span>Severity: Medium</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H" target="_blank" rel="noreferrer"><span>AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H</span></a><span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-1323" target="_blank" rel="noreferrer"><span>CVE-2026-1323</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noreferrer"><span>CWE-502</span></a><h3>Problem Description</h3>
<p>The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at <i>$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath']</i>.</p>
<h3>Solution</h3>
<p>Updated versions 0.5.2 and 0.4.5 are available from the TYPO3 extension manager, packagist and at</p>
<p><a href="https://extensions.typo3.org/extension/download/mailqueue/0.4.5/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/mailqueue/0.4.5/zip</a><br><a href="https://extensions.typo3.org/extension/download/mailqueue/0.5.2/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/mailqueue/0.5.2/zip</a></p>
<p>Users of the extension are advised to update the extension as soon as possible.</p>
<h3>Credits</h3>
<p>Thanks to TYPO3 security team member Elias Häußler for reporting the vulnerability and for providing updated versions of the extension.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1961</guid>
                        <pubDate>Fri, 13 Mar 2026 11:29:38 +0100</pubDate>
                        <title>This Month in TYPO3: February, 2026</title>
                        <link>https://news.typo3.com/article/this-month-in-typo3-february-2026</link>
                        <description>February kept the momentum going. Two maintenance releases kept production stable, the Board dropped an activity report, and nominations opened for Board and Business Control Committee seats. Content Blocks cleared the v14 milestone, and Europe&#039;s digital sovereignty shift moved TYPO3 into sharper strategic focus. March has a packed calendar waiting.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/e/0/csm_This-Month-In-TYPO3-Feb-2026_1b4011b98c.webp" length="80278" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1959</guid>
                        <pubDate>Thu, 12 Mar 2026 09:48:32 +0100</pubDate>
                        <title>My First Day on the Frontline — Report From a Best Practice Remote Code Sprint</title>
                        <link>https://news.typo3.com/article/my-first-day-on-the-frontline-report-from-best-practice-remote-code-sprint</link>
                        <description>With the new year just around the corner, I attended a Remote Code Sprint of the Best Practices Team for the very first time ever.</description>
                        
                        
                        
                            
                                <category>Personal Stories &amp; Opinions</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/8/9/csm_Best_Practice_Remote_Code_Sprint_991d0ae253.webp" length="369334" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1954</guid>
                        <pubDate>Wed, 11 Mar 2026 07:00:00 +0100</pubDate>
                        <title>First TYPO3 Marketing Sprint 2026 in Berlin</title>
                        <link>https://news.typo3.com/article/first-typo3-marketing-sprint-2026-in-berlin</link>
                        <description>Help us shape the official TYPO3 v14 LTS narrative! Join the hybrid Marketing Sprint in Berlin on April 13-14, 2026. Secure your spot and register now.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/2/5/csm_sprint_9af86780ef.webp" length="583372" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1958</guid>
                        <pubDate>Tue, 10 Mar 2026 13:30:00 +0100</pubDate>
                        <title>TYPO3 13.4.27 and 12.4.44 maintenance releases published</title>
                        <link>https://news.typo3.com/article/typo3-13427-and-12444-maintenance-releases-published</link>
                        <description>The versions 13.4.27 and 12.4.44 of the TYPO3 Enterprise Content Management System have just been released.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_7e4b56f244.webp" length="164480" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1952</guid>
                        <pubDate>Tue, 10 Mar 2026 07:50:00 +0100</pubDate>
                        <title>From Billable Hours to Scalable Products</title>
                        <link>https://news.typo3.com/article/from-billable-hours-to-scalable-products</link>
                        <description>Digital agencies typically grow by taking on more projects and increasing team capacity. This model works well for delivering client services, but it also creates a structural limit: revenue remains closely tied to billable time.</description>
                        
                        
                        
                            
                                <category>Market &amp; Sell</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/f/e/csm_code-sprint_laptop_03_996e227cb6.webp" length="116164" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1926</guid>
                        <pubDate>Mon, 09 Mar 2026 07:00:00 +0100</pubDate>
                        <title>TYPO3 Returns to CloudFest 2026</title>
                        <link>https://news.typo3.com/article/typo3-returns-to-cloudfest-2026</link>
                        <description>TYPO3 returns to CloudFest 2026. Explore how we’re collaborating with the FAIR project and Open Website Alliance to prepare for the Cyber Resilience Act.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/8/9/csm_IMG_7086_ce3906cb40.webp" length="417786" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1945</guid>
                        <pubDate>Wed, 04 Mar 2026 16:12:20 +0100</pubDate>
                        <title>Second Call for Community Budget Ideas in 2026</title>
                        <link>https://news.typo3.com/article/second-call-for-community-budget-ideas-in-2026</link>
                        <description>The TYPO3 Association has officially launched the second community budget idea process of 2026. This is the second round of  the refreshed, more focused approach to funding community-driven and team-driven initiatives.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/TYPO3_Stock/Icon_Designs/TYPO3_Circles_Lightbulb_Exclamation_On.svg" length="5455" type="image/svg+xml"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1923</guid>
                        <pubDate>Tue, 03 Mar 2026 07:11:00 +0100</pubDate>
                        <title>New TYPO3 Certification Pricing and Bundle Offer – Effective March 2026</title>
                        <link>https://news.typo3.com/article/new-certification-pricing-bundle</link>
                        <description>Discover the new TYPO3 certification pricing and bundle model effective March 2026. Transparent costs, mock exams, and two-year planning security.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/5/e/csm_Certifications_img_bb39ef6c59.webp" length="206416" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1918</guid>
                        <pubDate>Mon, 02 Mar 2026 19:58:40 +0100</pubDate>
                        <title>Getting TYPO3 v14 Over the Finish Line: Our Week at the Rosenheim Code Sprint</title>
                        <link>https://news.typo3.com/article/getting-typo3-v14-over-the-finish-line-our-week-at-the-rosenheim-code-sprint</link>
                        <description>With a clear mission to complete outstanding v14 tasks, Marno shares the highlights from our team sprint in Rosenheim, Germany, where collaboration and focused effort brought us closer to the final release.</description>
                        
                        
                        
                            
                                <category>Personal Stories &amp; Opinions</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/b/6/csm_IMG_1867_6a14986d63.webp" length="622286" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1919</guid>
                        <pubDate>Mon, 02 Mar 2026 13:49:23 +0100</pubDate>
                        <title>TYPO3 Contribution in Numbers: February 2026</title>
                        <link>https://news.typo3.com/article/typo3-contribution-in-numbers-february-2026</link>
                        <description>See the full recap of TYPO3&#039;s February core contributions with 76 contributors, 239 reviews, bug fixes, features, and a big thank-you to our developers.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/c/0/csm_DAD_listing_1400x933_LAY01__1__45cdadc4fa.webp" length="170804" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1905</guid>
                        <pubDate>Thu, 26 Feb 2026 09:11:00 +0100</pubDate>
                        <title>We Are Looking for Candidates for the Board and Business Control Committee</title>
                        <link>https://news.typo3.com/article/we-are-looking-for-candidates-for-the-board-and-business-control-committee</link>
                        <description>Are you a passionate member of the community? Do you have a vision for TYPO3&#039;s future? Whether you are a developer or a non-code contributor, TYPO3 needs dedicated people to help guide the project and serve the community.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/7/8/csm_TYPO3_Board_and_BCC_Candidates_e1eeac997a.webp" length="318318" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1904</guid>
                        <pubDate>Wed, 25 Feb 2026 09:50:32 +0100</pubDate>
                        <title>The TYPO3 Camp Baden-Württemberg Is Back!</title>
                        <link>https://news.typo3.com/article/the-typo3-camp-baden-wuerttemberg-is-back</link>
                        <description>This German-language event brings together the TYPO3 community for two days of knowledge exchange and collaboration.</description>
                        
                        
                        
                            
                                <category>Best Practice &amp; Learning</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/1/f/csm_TYPO3_Camp_Baden-W%C3%BCrttemberg_The_C%C3%A4mp_Logo_3_2_1c5ec2c81c.webp" length="29426" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1900</guid>
                        <pubDate>Tue, 24 Feb 2026 11:23:45 +0100</pubDate>
                        <title>Board Report: New Responsibilities, Community Work, and a Look-Out for 2026</title>
                        <link>https://news.typo3.com/article/board-report-new-responsibilities-community-work-and-a-look-out-for-2026</link>
                        <description>During the third and fourth quarter of 2025, the TYPO3 Board focused on strengthening governance structures, expanding cross-community networking, and driving technical innovation. From preparing for new EU regulations to active participation in international camps, here is an overview of the board&#039;s recent activities.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/2/2/csm_t3con25_typo3_booth_429123e7c3.webp" length="387290" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1893</guid>
                        <pubDate>Fri, 20 Feb 2026 10:30:00 +0100</pubDate>
                        <title>TYPO3 14.1.1, 13.4.26 and 12.4.43 maintenance releases published</title>
                        <link>https://news.typo3.com/article/typo3-1411-13426-and-12443-maintenance-releases-published</link>
                        <description>The versions 14.1.1, 13.4.26 and 12.4.43 of the TYPO3 Enterprise Content Management System have just been released.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_7e4b56f244.webp" length="164480" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1883</guid>
                        <pubDate>Thu, 19 Feb 2026 09:34:00 +0100</pubDate>
                        <title>Digital Sovereignty and Open Source: Europe’s Shifting Technology Foundations</title>
                        <link>https://news.typo3.com/article/digital-sovereignty-open-source-europe</link>
                        <description>European organizations are reassessing their tech stacks as digital sovereignty becomes a necessity. Learn why open source is emerging as a strategic alternative.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/4/2/csm_Stock_TYPO3_Laptop_9cce439c49.webp" length="454988" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1760</guid>
                        <pubDate>Thu, 12 Feb 2026 13:47:00 +0100</pubDate>
                        <title>Debunking 7 Common Myths about Open Source CMS</title>
                        <link>https://news.typo3.com/article/debunking-7-common-myths-about-open-source-cms</link>
                        <description>Debunk common myths about open source CMSs and learn how open source solutions like TYPO3 deliver security, scalability, innovation, and enterprise value.</description>
                        
                        
                        
                            
                                <category>Market &amp; Sell</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/a/c/csm_Debunking_7_common_myths_listing_1400x933_LAY02_ce6dc331e3.webp" length="94444" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1876</guid>
                        <pubDate>Thu, 12 Feb 2026 09:04:00 +0100</pubDate>
                        <title>In Memory of Jens Liesegang</title>
                        <link>https://news.typo3.com/article/in-memory-of-jens-liesegang</link>
                        <description>It is with great sadness that we learned of the passing of our esteemed colleague and companion Jens Liesegang.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/3/0/csm_Jens_Liesegang_347db1556b.webp" length="43962" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1872</guid>
                        <pubDate>Wed, 11 Feb 2026 15:02:02 +0100</pubDate>
                        <title>Content Blocks: Q4/2025 Milestones and Q1/2026 Goals</title>
                        <link>https://news.typo3.com/article/content-blocks-q4-2025-milestones-and-q1-2026-goals</link>
                        <description>The Content Types Team wrapped up the major milestone of TYPO3 v14 support and focused on the long-awaited Content Blocks GUI.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/d/8/csm_content_blocks_gui_3_vignette_9afc5a2f5f.webp" length="73514" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1870</guid>
                        <pubDate>Tue, 10 Feb 2026 11:00:00 +0100</pubDate>
                        <title>TYPO3 13.4.25 maintenance release published</title>
                        <link>https://news.typo3.com/article/typo3-13425-maintenance-release-published</link>
                        <description>The version 13.4.25 of the TYPO3 Enterprise Content Management System has just been released.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_7e4b56f244.webp" length="164480" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1832</guid>
                        <pubDate>Thu, 05 Feb 2026 00:00:00 +0100</pubDate>
                        <title>Community Budget Report: A PHP Firewall for TYPO3</title>
                        <link>https://news.typo3.com/article/community-budget-report-a-php-firewall-for-typo3</link>
                        <description>Sascha Egerer provides an update on his Community Budget Idea to add a PHP-based firewall to TYPO3, helping site owners block common attacks even when they can’t rely on server-level security.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/Blog-Content/2026/01/firewall/typo3_firewall_icon_with_background.svg" length="72168" type="image/svg+xml"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1813</guid>
                        <pubDate>Tue, 03 Feb 2026 08:49:55 +0100</pubDate>
                        <title>Generating QR codes with TYPO3 v14</title>
                        <link>https://news.typo3.com/article/generating-qr-codes-with-typo3-v14</link>
                        <description>With version 14.1 editors now have the ability to generate and download QR codes and have them link back to pages in the page tree.</description>
                        
                        
                        
                            
                                <category>Best Practice &amp; Learning</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/6/e/csm_0.Hero_ca49ea073c.webp" length="63232" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1814</guid>
                        <pubDate>Mon, 02 Feb 2026 16:00:00 +0100</pubDate>
                        <title>TYPO3 Contribution in Numbers: January 2026</title>
                        <link>https://news.typo3.com/article/typo3-contribution-in-numbers-january-2026</link>
                        <description>See the full recap of TYPO3’s January core contributions with 53 contributors, 163 reviews, bug fixes, features, and a big thank-you to our developers.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/c/0/csm_DAD_listing_1400x933_LAY01__1__45cdadc4fa.webp" length="170804" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1812</guid>
                        <pubDate>Mon, 02 Feb 2026 11:15:31 +0100</pubDate>
                        <title>This Month in TYPO3: January 2026</title>
                        <link>https://news.typo3.com/article/this-month-in-typo3-january-2026</link>
                        <description>New year, new vibe. The v14.1 announcement and Camino, the new default theme, give TYPO3 a fresh look, and security releases keep production calm. A thoughtful note on open-source AI stewardship and four funded community ideas for Round One 2026 set an optimistic tone for the year.</description>
                        
                        
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/d/9/csm_This-Month-In-TYPO3-Jan-2026_a4fe7970e6.webp" length="80822" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1766</guid>
                        <pubDate>Thu, 29 Jan 2026 11:41:00 +0100</pubDate>
                        <title>Introducing Camino – TYPO3&#039;s New Default Theme</title>
                        <link>https://news.typo3.com/article/introducing-camino-typo3s-new-default-theme</link>
                        <description>Earlier this month we saw the release of TYPO3 14.1 and with it came the introduction of Camino – TYPO3’s new default theme.</description>
                        
                        
                        
                            
                                <category>Best Practice &amp; Learning</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/2/a/csm_IntroductionCaminoTheme_df5fb79039.webp" length="155204" type="image/png"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1757</guid>
                        <pubDate>Wed, 28 Jan 2026 00:00:00 +0100</pubDate>
                        <title>Members Have Selected Four Ideas to be Funded in Round One 2026</title>
                        <link>https://news.typo3.com/article/members-have-selected-four-ideas-to-be-funded-in-round-one-2026</link>
                        <description>The TYPO3 Association member poll for Round One in 2026 budget ideas has been finished and this time four winning ideas will be funded by the TYPO3 Association.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/TYPO3_Stock/Icon_Designs/TYPO3_Circles_Wreath_Laurel_Dollar.svg" length="8070" type="image/svg+xml"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1756</guid>
                        <pubDate>Tue, 27 Jan 2026 12:00:00 +0100</pubDate>
                        <title>TYPO3 Association Board Report January–August 2025</title>
                        <link>https://news.typo3.com/article/typo3-association-board-report-january-august-2025</link>
                        <description>This report gives insights into the TYPO3 Association Board’s activities during the first eight months of 2025, as well as some background information on ongoing projects and processes. It also recaps the General Assembly and gives insights into the Board’s strategic focus areas for the year.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/b/3/csm_typo3_association_board_karlsruhe_august_2025_3c7b38fb31.webp" length="472116" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1745</guid>
                        <pubDate>Thu, 22 Jan 2026 13:40:35 +0100</pubDate>
                        <title>Open Source, AI, and the Need for Shared Stewardship</title>
                        <link>https://news.typo3.com/article/open-source-ai-and-the-need-for-shared-stewardship</link>
                        <description>In this conversation starter, Olivier Dobberkau outlines the pressures facing open source in the age of AI, and invites the TYPO3 community to rethink stewardship, responsibility, and sustainability together.</description>
                        
                        
                        
                            
                                <category>Personal Stories &amp; Opinions</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/4/5/csm_olivier_dobberkau_2026_adcaad1cbf.webp" length="298430" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1743</guid>
                        <pubDate>Tue, 20 Jan 2026 13:46:00 +0100</pubDate>
                        <title>TYPO3 v14.1—New Look, New Feel</title>
                        <link>https://news.typo3.com/article/typo3-v141-new-look-new-feel</link>
                        <description>The second sprint release of the TYPO3 v14 series comes with an awesome frontend theme out-of-the-box, further user interface optimization in the backend, a new module to generate QR codes, plus a range of updates and improvements.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/4/5/csm_v14_1_1600x1066_LAY01_28a911287e.webp" length="42082" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2919</guid>
                        <pubDate>Tue, 20 Jan 2026 08:33:00 +0100</pubDate>
                        <title>Vulnerability in bundled package in extension &quot;Amazon AWS SDK&quot; (aws)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-004</link>
                        <description>It has been discovered that the extension &quot;Amazon AWS SDK&quot; (aws) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: January 20, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/aws" target="_blank" rel="noreferrer"><span>"Amazon AWS SDK" (aws)</span></a><span>Composer Package Name: Not available</span><span>Vulnerability Type: Broken or Risky Cryptographic Algorithm</span><span>Affected Versions: 3.161.2 and below</span><span>Severity: Medium</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</span></a><span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-14761" target="_blank" rel="noreferrer"><span>CVE-2025-14761</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/1395.html" target="_blank" rel="noreferrer"><span>CWE-1395</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/327.html" target="_blank" rel="noreferrer"><span>CWE-327</span></a><h3>Problem Description</h3>
<p>The extension bundles the PHP package “aws/aws-sdk-php”, which contains a known <a href="https://aws.amazon.com/de/security/security-bulletins/rss/aws-2025-032/" target="_blank" rel="noreferrer">Broken or Risky Cryptographic Algorithm</a> vulnerability.</p>
<h3>Solution</h3>
<p>All versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository, because the extension is outdated and unmaintained.</p>
<p>Please uninstall and delete the extension folder from your installation and search on the <a href="https://extensions.typo3.org/" target="_blank" rel="noreferrer">TYPO3 Extension Repository</a> for alternative extensions.</p>
<h3>Credits</h3>
<p>Thanks to Michael Schams &nbsp;for reporting the vulnerability.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2918</guid>
                        <pubDate>Tue, 20 Jan 2026 08:32:00 +0100</pubDate>
                        <title>Vulnerability in bundled package in extension &quot;Amazon Web Services (AWS) Toolbox&quot; (aws_tools)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-003</link>
                        <description>It has been discovered that the extension &quot;Amazon Web Services (AWS) Toolbox&quot; (aws_tools) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: January 20, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/aws_tools" target="_blank" rel="noreferrer"><span>"Amazon Web Services (AWS) Toolbox" (aws_tools)</span></a><span>Composer Package Name: leuchtfeuer/aws-tools</span><span>Vulnerability Type: Broken or Risky Cryptographic Algorithm</span><span>Affected Versions: 12.0.0 - 12.0.1, 11.0.3 and below</span><span>Severity: Medium</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</span></a>&nbsp;<span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-14761" target="_blank" rel="noreferrer"><span>CVE-2025-14761</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/1395.html" target="_blank" rel="noreferrer"><span>CWE-1395</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/327.html" target="_blank" rel="noreferrer"><span>CWE-327</span></a><h3>Problem Description</h3>
<p>The extension bundles the PHP package “aws/aws-sdk-php”, which contains a known <a href="https://aws.amazon.com/de/security/security-bulletins/rss/aws-2025-032/" target="_blank" rel="noreferrer">Broken or Risky Cryptographic Algorithm</a> vulnerability.</p>
<h3>Solution</h3>
<p>Updated versions 11.0.4 and 12.0.2 are available from the TYPO3 extension manager, packagist and at</p>
<p><a href="https://extensions.typo3.org/extension/download/aws_tools/11.0.3/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/aws_tools/11.0.3/zip</a><br><a href="https://extensions.typo3.org/extension/download/aws_tools/12.0.2/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/aws_tools/12.0.2/zip</a></p>
<p>Users of the extension are advised to update the extension as soon as possible.</p>
<h3>Credits</h3>
<p>Thanks to Michael Schams &nbsp;for reporting the vulnerability and to Leuchtfeuer Digital Marketing for providing updated versions of the extension.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2917</guid>
                        <pubDate>Tue, 20 Jan 2026 08:31:00 +0100</pubDate>
                        <title>Vulnerability in bundled package in extension &quot;AWS SDK for PHP&quot; (aws_sdk_php)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-002</link>
                        <description>It has been discovered that the extension &quot;AWS SDK for PHP&quot; (aws_sdk_php) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: January 20, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/aws_sdk_php" target="_blank" rel="noreferrer"><span>"AWS SDK for PHP" (aws_sdk_php)</span></a><span>Composer Package Name: Not available</span><span>Vulnerability Type: Broken or Risky Cryptographic Algorithm</span><span>Affected Versions: 3.367.3 and below</span><span>Severity: Medium</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</span></a><span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2025-14761" target="_blank" rel="noreferrer"><span>CVE-2025-14761</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/1395.html" target="_blank" rel="noreferrer"><span>CWE-1395</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/327.html" target="_blank" rel="noreferrer"><span>CWE-327</span></a><h3>Problem Description</h3>
<p>The extension bundles the PHP package “aws/aws-sdk-php”, which contains a known&nbsp;<a href="https://aws.amazon.com/de/security/security-bulletins/rss/aws-2025-032/" target="_blank" rel="noreferrer">Broken or Risky Cryptographic Algorithm</a> vulnerability.</p>
<h3>Solution</h3>
<p>An updated version 3.368.0 is available from the TYPO3 extension manager at</p>
<p><a href="https://extensions.typo3.org/extension/download/aws_sdk_php/3.368.0/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/aws_sdk_php/3.368.0/zip</a></p>
<p>Users of the extension are advised to update the extension as soon as possible.</p>
<h3>Credits</h3>
<p>Thanks to Michael Schams &nbsp;for reporting the vulnerability and for providing an updated version of the extension.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2916</guid>
                        <pubDate>Tue, 20 Jan 2026 08:30:00 +0100</pubDate>
                        <title>Insecure Deserialization in extension &quot;Mailqueue&quot; (mailqueue)</title>
                        <link>https://news.typo3.com/archive/typo3-ext-sa-2026-001</link>
                        <description>It has been discovered that the extension &quot;Mailqueue&quot; (mailqueue) is vulnerable to insecure deserialization.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<span>Release Date: January 20, 2026</span><span>Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.</span><span>Component: </span><a href="https://extensions.typo3.org/extension/mailqueue" target="_blank" rel="noreferrer"><span>"Mailqueue" (mailqueue)</span></a><span>Composer Package Name: cpsit/typo3-mailqueue</span><span>Vulnerability Type: Insecure Deserialization</span><span>Affected Versions: 0.5.0, 0.4.2 and below</span><span>Severity: Medium</span><span>Suggested CVSS v4.0: </span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H" target="_blank" rel="noreferrer"><span>AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H</span></a><span>References: </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-0895" target="_blank" rel="noreferrer"><span>CVE-2026-0895</span></a><span>, </span><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noreferrer"><span>CWE-502</span></a><h3>Problem Description</h3>
<p>The extension extends TYPO3’s <i>FileSpool</i> component, which was vulnerable to Insecure Deserialization prior to <a href="https://typo3.org/security/advisory/typo3-core-sa-2026-004" target="_blank">TYPO3-CORE-SA-2026-004</a>. Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core version still allows for Insecure Deserialization, because the affected vulnerable code was extracted from TYPO3 core to the extension.</p>
<p>More information about this vulnerability can be found in the related TYPO3 Core Security Advisory <a href="https://typo3.org/security/advisory/typo3-core-sa-2026-004" target="_blank">TYPO3-CORE-SA-2026-004</a>.</p>
<h3>Solution</h3>
<p>Updated versions 0.5.1 and 0.4.3 are available from the TYPO3 extension manager, packagist and at</p>
<p><a href="https://extensions.typo3.org/extension/download/mailqueue/0.4.3/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/mailqueue/0.4.3/zip</a><br><a href="https://extensions.typo3.org/extension/download/mailqueue/0.5.1/zip" target="_blank" rel="noreferrer">https://extensions.typo3.org/extension/download/mailqueue/0.5.1/zip</a></p>
<p>Users of the extension are advised to update the extension as soon as possible.</p>
<h3>Credits</h3>
<p>Thanks to TYPO3 security team member Elias Häußler for reporting the vulnerability and for providing updated versions of the extension.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce mailing</a> list.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1742</guid>
                        <pubDate>Tue, 20 Jan 2026 08:30:00 +0100</pubDate>
                        <title>TYPO3 10.4.56 and 11.5.50 ELTS Released</title>
                        <link>https://news.typo3.com/article/typo3-10456-and-11550-elts-released</link>
                        <description>Still sticking to an older version of TYPO3? Today, 10.4.56 and 11.5.50 have been released. Staying on top of maintenance updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/6/c/csm_ELTS_Release_listing_1400x933_LAY02_7357ab44f3.webp" length="154362" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1744</guid>
                        <pubDate>Tue, 20 Jan 2026 08:30:00 +0100</pubDate>
                        <title>TYPO3 13.4.24 and 12.4.42 maintenance releases published</title>
                        <link>https://news.typo3.com/article/typo3-13424-and-12442-maintenance-releases-published</link>
                        <description>The versions 13.4.24 and 12.4.42 of the TYPO3 Enterprise Content Management System have just been released.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/0/6/csm_Maintenance_Release_listing_1400x933_LAY01_7e4b56f244.webp" length="164480" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1740</guid>
                        <pubDate>Thu, 15 Jan 2026 16:34:18 +0100</pubDate>
                        <title>AI Integration in TYPO3 Via MCP: The End of Backend Fumbling</title>
                        <link>https://news.typo3.com/article/ai-integration-in-typo3-via-mcp-the-end-of-backend-fumbling</link>
                        <description>Content management meets artificial intelligence — and takes a quantum leap. With the Model Context Protocol (MCP) extension for TYPO3, editors control their content directly from ChatGPT &amp; Co. No more copy-paste, no more backend hopping. Simply write, edit, publish — all in one tool.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/4/5/csm_image1_vignette_0a1dc26b28.webp" length="74014" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1737</guid>
                        <pubDate>Tue, 13 Jan 2026 13:00:00 +0100</pubDate>
                        <title>TYPO3 14.0.2, 13.4.23 and 12.4.41 security releases published</title>
                        <link>https://news.typo3.com/article/typo3-1402-13423-and-12441-security-releases-published</link>
                        <description>The versions 14.0.2, 13.4.23 and 12.4.41 of the TYPO3 Enterprise Content Management System have just been released.</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/7/e/csm_Security_Release_listing_1400x933_LAY01_8492726a03.webp" length="164294" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1736</guid>
                        <pubDate>Tue, 13 Jan 2026 12:59:00 +0100</pubDate>
                        <title>TYPO3 10.4.55 and 11.5.49 ELTS Released</title>
                        <link>https://news.typo3.com/article/typo3-10455-and-11549-elts-released</link>
                        <description>Still sticking to an older version of TYPO3? Today, 10.4.55 and 11.5.49 have been released. Staying on top of maintenance updates should be a top priority - Gain peace of mind by opting for one of TYPO3 GmbH’s Extended Support offers!</description>
                        
                        
                        
                            
                                <category>Product Updates &amp; Roadmap</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/6/c/csm_ELTS_Release_listing_1400x933_LAY02_7357ab44f3.webp" length="154362" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2915</guid>
                        <pubDate>Tue, 13 Jan 2026 12:04:00 +0100</pubDate>
                        <title>Insecure Deserialization via Mailer File Spool</title>
                        <link>https://news.typo3.com/archive/typo3-core-sa-2026-004</link>
                        <description>It has been discovered that TYPO3 CMS is vulnerable to insecure deserialization.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<hr><strong>Component Type:</strong><span> TYPO3 CMS</span><strong>Subcomponent:</strong><span> Mailer (ext:core)</span><strong>Release Date:</strong><span> January 13, 2026</span><strong>Vulnerability Type:</strong><span> Insecure Deserialization</span><strong>Affected Versions:</strong><span> 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22, 14.0.0-14.0.1</span><strong>Severity:</strong><span> Medium</span><strong>Suggested CVSS:</strong><span>&nbsp;</span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H" target="_blank" rel="noreferrer"><span>CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H</span></a><strong>References:</strong><span>&nbsp;</span><a href="https://www.cve.org/CVERecord?id=CVE-2026-0859" target="_blank" rel="noreferrer"><span>CVE-2026-0859</span></a><span>,&nbsp;</span><a href="https://cwe.mitre.org/data/definitions/502.html" target="_blank" rel="noreferrer"><span>CWE-502</span></a><hr>
<h3>Problem Description</h3>
<p>Local platform users who can write to TYPO3’s mail‑file spool directory can craft a file that the system will automatically deserialize without any class restrictions. This flaw allows an attacker to inject and execute arbitrary PHP code in the public scope of the web server.</p>
<p>The vulnerability is triggered when TYPO3 is configured with&nbsp;<i>$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_type'] = 'file';</i> and a scheduler task or cron job runs the command&nbsp;<i>mailer:spool:send</i>. The spool‑send operation performs the insecure deserialization that is at the core of this issue.</p>
<h3>Solution</h3>
<p>Update to TYPO3 versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2 that fix the problem described.</p>
<h3>Credits</h3>
<p>Thanks to Vitaly Simonovich for reporting this issue, and to TYPO3 security team members Elias Häußler and Oliver Hader for fixing it.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce</a> mailing list.</p>
<h3>General Note</h3>
<p>All security-related code changes are tagged so you can easily look them up in our <a href="https://review.typo3.org/#/q/status:merged+project:Packages/TYPO3.CMS+topic:security,n,z" target="_blank" rel="noreferrer">review system</a>.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                                <category>TYPO3 CMS</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2914</guid>
                        <pubDate>Tue, 13 Jan 2026 12:03:00 +0100</pubDate>
                        <title>Broken Access Control in Recycler Module</title>
                        <link>https://news.typo3.com/archive/typo3-core-sa-2026-003</link>
                        <description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<hr><strong>Component Type:</strong><span> TYPO3 CMS</span><strong>Subcomponent:</strong><span> Recycler (ext:recycler)</span><strong>Release Date:</strong><span> January 13, 2026</span><strong>Vulnerability Type:</strong><span> Broken Access Control</span><strong>Affected Versions:</strong><span> 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22, 14.0.0-14.0.1</span><strong>Severity:</strong><span> High</span><strong>Suggested CVSS:</strong><span>&nbsp;</span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</span></a><strong>References:</strong><span>&nbsp;</span><a href="https://www.cve.org/CVERecord?id=CVE-2025-59022" target="_blank" rel="noreferrer"><span>CVE-2025-59022</span></a><span>,&nbsp;</span><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noreferrer"><span>CWE-862</span></a><hr>
<h3>Problem Description</h3>
<p>Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering the website unavailable.</p>
<h3>Solution</h3>
<p>Update to TYPO3 versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2 that fix the problem described.</p>
<h3>Credits</h3>
<p>Thanks to Sven Jürgens and Daniel Windloff for reporting this issue, and to TYPO3 security team member Elias Häußler for fixing it.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce</a> mailing list.</p>
<h3>General Note</h3>
<p>All security-related code changes are tagged so you can easily look them up in our <a href="https://review.typo3.org/#/q/status:merged+project:Packages/TYPO3.CMS+topic:security,n,z" target="_blank" rel="noreferrer">review system</a>.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                                <category>TYPO3 CMS</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2913</guid>
                        <pubDate>Tue, 13 Jan 2026 12:02:00 +0100</pubDate>
                        <title>Broken Access Control in Redirects Module</title>
                        <link>https://news.typo3.com/archive/typo3-core-sa-2026-002</link>
                        <description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<hr><strong>Component Type:</strong><span> TYPO3 CMS</span><strong>Subcomponent:</strong><span> Redirects (ext:redirects)</span><strong>Release Date:</strong><span> January 13, 2026</span><strong>Vulnerability Type:</strong><span> Broken Access Control</span><strong>Affected Versions:</strong><span> 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22, 14.0.0-14.0.1</span><strong>Severity:</strong><span> Medium</span><strong>Suggested CVSS:</strong><span>&nbsp;</span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N" target="_blank" rel="noreferrer"><span>CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N</span></a><strong>References:</strong><span>&nbsp;</span><a href="https://www.cve.org/CVERecord?id=CVE-2025-59021" target="_blank" rel="noreferrer"><span>CVE-2025-59021</span></a><span>,&nbsp;</span><a href="https://cwe.mitre.org/data/definitions/862.html" target="_blank" rel="noreferrer"><span>CWE-862</span></a><hr>
<h3>Problem Description</h3>
<p>Backend users with access to the redirects module and write permission on the&nbsp;<i>sys_redirect</i> table were able to&nbsp; read, create, and modify any redirect record - without restriction to the user’s own file‑mounts or web‑mounts. This allowed attackers to insert or alter redirects pointing to arbitrary URLs - facilitating phishing or other malicious redirect attacks.</p>
<h3>Solution</h3>
<p>Update to TYPO3 versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2 that fix the problem described.</p>
<h3>Credits</h3>
<p>Thanks to Georg Dümmler for reporting this issue, and to TYPO3 security team member Elias Häußler for fixing it.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce</a> mailing list.</p>
<h3>General Note</h3>
<p>All security-related code changes are tagged so you can easily look them up in our <a href="https://review.typo3.org/#/q/status:merged+project:Packages/TYPO3.CMS+topic:security,n,z" target="_blank" rel="noreferrer">review system</a>.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                                <category>TYPO3 CMS</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">news-2912</guid>
                        <pubDate>Tue, 13 Jan 2026 12:01:00 +0100</pubDate>
                        <title>Broken Access Control in Edit Document Controller</title>
                        <link>https://news.typo3.com/archive/typo3-core-sa-2026-001</link>
                        <description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description>
                        
                        
                            
                            <content:encoded><![CDATA[<hr><strong>Component Type:</strong><span> TYPO3 CMS</span><strong>Subcomponent:</strong><span> Edit Document Controller (ext:backend)</span><strong>Release Date:</strong><span> January 13, 2026</span><strong>Vulnerability Type:</strong><span> Broken Access Control</span><strong>Affected Versions:</strong><span> 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22, 14.0.0-14.0.1</span><strong>Severity:</strong><span> Medium</span><strong>Suggested CVSS:</strong><span>&nbsp;</span><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator?vector=AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L" target="_blank" rel="noreferrer"><span>CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L</span></a><strong>References:</strong><span>&nbsp;</span><a href="https://www.cve.org/CVERecord?id=CVE-2025-59020" target="_blank" rel="noreferrer"><span>CVE-2025-59020</span></a><span>,&nbsp;</span><a href="https://cwe.mitre.org/data/definitions/863.html" target="_blank" rel="noreferrer"><span>CWE-863</span></a><hr>
<h3>Problem Description</h3>
<p>By exploiting the <i>defVals</i> parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set of fields.</p>
<h3>Solution</h3>
<p>Update to TYPO3 versions 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2 that fix the problem described.</p>
<h3>Credits</h3>
<p>Thanks to Daniel Windloff for reporting this issue, and to TYPO3 core &amp; security team member Benjamin Franzke for fixing it.</p>
<h3>General Advice</h3>
<p>Follow the recommendations that are given in the <a href="https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html#security" target="_blank" rel="noreferrer">TYPO3 Security Guide</a>. Please subscribe to the <a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">typo3-announce</a> mailing list.</p>
<h3>General Note</h3>
<p>All security-related code changes are tagged so you can easily look them up in our <a href="https://review.typo3.org/#/q/status:merged+project:Packages/TYPO3.CMS+topic:security,n,z" target="_blank" rel="noreferrer">review system</a>.</p>]]></content:encoded>
                        
                        
                            
                                <category>Development</category>
                            
                                <category>TYPO3 CMS</category>
                            
                        
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1727</guid>
                        <pubDate>Thu, 08 Jan 2026 08:05:43 +0100</pubDate>
                        <title>Recognizing Open-Source Work as Volunteering in Germany</title>
                        <link>https://news.typo3.com/article/recognizing-open-source-work-as-volunteering-in-germany</link>
                        <description>TYPO3 Association Board member Boris Hinzer outlines a new petition advocating for legal recognition of open-source work as volunteer service.</description>
                        
                        
                        
                            
                                <category>Personal Stories &amp; Opinions</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/6/9/csm_Reichstag__Berl%C3%ADn__Alemania__2016-04-21__DD_46-48_HDR_cf49f6e78b.webp" length="481310" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1725</guid>
                        <pubDate>Thu, 08 Jan 2026 07:44:00 +0100</pubDate>
                        <title>Coder&#039;s Corner: December 2025</title>
                        <link>https://news.typo3.com/article/coders-corner-december-2025</link>
                        <description>See the full recap of TYPO3’s November core contributions with 47 contributors, 148 reviews, bug fixes, features, and a big thank-you to our developers.</description>
                        
                        
                        
                            
                                <category>Developer &amp; Technology</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/5/0/csm_DAD_blog_11_Nov_43c9883efb.webp" length="157110" type="image/jpeg"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1724</guid>
                        <pubDate>Wed, 07 Jan 2026 11:13:29 +0100</pubDate>
                        <title>Vote Now! Budget Ideas for Round 1/2026 Have Been Published</title>
                        <link>https://news.typo3.com/article/vote-now-budget-ideas-for-round-1-2026-have-been-published</link>
                        <description>The call for community budget ideas for the first round of 2026 was successful: Six community and three team ideas have made it to the poll. These ideas can now be discussed and TYPO3 Association members can cast their vote.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/TYPO3_Stock/Icon_Designs/TYPO3_Circles_Ballot_Check_Dollar.svg" length="5556" type="image/svg+xml"/>
                        
                    </item>
                
                    <item>
                        <guid isPermaLink="false">post-1723</guid>
                        <pubDate>Tue, 06 Jan 2026 14:00:14 +0100</pubDate>
                        <title>This Month in TYPO3: December 2025</title>
                        <link>https://news.typo3.com/article/this-month-in-typo3-december-2025</link>
                        <description>December closed out 2025 with solid releases and active community work. From security updates and tooling progress to conference highlights and upcoming events, this roundup captures where TYPO3 stands as it heads into 2026 — and introduces a new This Month in TYPO3 editor.</description>
                        
                        
                        
                            
                                <category>The Project</category>
                            
                        
                        
                            
                            <enclosure url="https://news.typo3.com/fileadmin/_processed_/b/8/csm_This-Month-In-TYPO3-December-2025_6651816410.webp" length="80432" type="image/jpeg"/>
                        
                    </item>
                
            
        </channel>
    </rss>

