Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
TYPO3-CORE-SA-2019-013: Cross-Site Scripting in Fluid Engine
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2019-012: Possible Arbitrary Code Execution in Image Processing
It has been discovered, that TYPO3 CMS is vulnerable to arbitrary code execution.
TYPO3-CORE-SA-2019-011: Security Misconfiguration in User Session Handling
It has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2019-010: Information Disclosure in User Authentication
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2019-009: Information Disclosure in Page Tree
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2019-008: Arbitrary Code Execution via File List Module
It has been discovered, that TYPO3 CMS is vulnerable to arbitrary code execution.
TYPO3-CORE-SA-2019-007: Cross-Site Scripting in Form Framework
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2019-006: Cross-Site Scripting in Bootstrap CSS toolkit
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2019-005: Cross-Site Scripting in Fluid ViewHelpers
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-EXT-SA-2019-004: Object Injection in extension "mkmailer" (mkmailer)
It has been discovered that the extension "mkmailer" (mkmailer) is susceptible to Object Injection.