Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-CORE-SA-2019-019: Arbitrary Code Execution and Cross-Site Scripting in Backend API
It has been discovered, that TYPO3 CMS is vulnerable to arbitrary code execution and cross-site scripting.
TYPO3-CORE-SA-2019-018: Security Misconfiguration in Frontend Session Handling
It has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2019-017: Broken Access Control in Import Module
It has been discovered, that TYPO3 CMS is susceptible to broken access control.
TYPO3-CORE-SA-2019-016: Possible deserialization side-effects in symfony/cache
It has been discovered that a third party dependency used by TYPO3 CMS is susceptible of being used during insecure deserialization.
TYPO3-CORE-SA-2019-015: Cross-Site Scripting in Link Handling
It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2019-014: Information Disclosure in Backend User Interface
It has been discovered that TYPO3 CMS is susceptible to information disclosure.
TYPO3-PSA-2019-008: By-passing protection of Phar Stream Wrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
TYPO3-EXT-SA-2019-013: SQL Injection in extension "comsolit Suggest" (comsolit_suggest)
It has been discovered that the extension "comsolit Suggest" (comsolit_suggest) is susceptible to SQL Injection.
TYPO3-EXT-SA-2019-012: Arbitrary file Upload in extension "Yet Another Gallery" (yag)
It has been discovered that the extension "Yet Another Gallery" (yag) is susceptible to Arbitrary File Upload.