Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-PSA-2023-001: Important Security-Bulletin Pre-Announcement
The TYPO3 Security Team pre-announces an important security release.
TYPO3-EXT-SA-2023-001: Broken Access Control in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is susceptible to Broken Access Control.
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
It has been discovered that the extension "Master-Quiz" (fp_masterquiz) is susceptible to Information Disclosure and Broken Access Control.
TYPO3-EXT-SA-2022-017: Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
It has been discovered that the extension "Newsletter subscriber management" (fp_newsletter) is susceptible to Information Disclosure and Broken Access Control.
TYPO3-EXT-SA-2022-016: Insufficient Session Expiration after Password Change in extension "Change password for frontend users" (fe_change_pwd)
It has been discovered that the extension "Change password for frontend users" (fe_change_pwd) is susceptible to insufficient session expiration.
TYPO3-CORE-SA-2022-017: By-passing Cross-Site Scripting Protection in HTML Sanitizer
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2022-016: Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
It has been discovered that TYPO3 CMS is susceptible to sensitive information disclosure.
TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework
It has been discovered that TYPO3 CMS is vulnerable to arbitrary code execution.
TYPO3-CORE-SA-2022-014: Insufficient Session Expiration after Password Reset
It has been discovered that TYPO3 CMS is susceptible to insufficient session expiration.
TYPO3-CORE-SA-2022-013: Weak Authentication in Frontend Login
It has been discovered that TYPO3 CMS is susceptible to weak authentication.