Security Advisories
All Advisories
Follow TYPO3 security advisories as soon as they are published by subscribing to the dedicated security RSS feed.
SECURITY-ISSUES-IN-SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS-INCLUDING-SR-FEUSER-REGISTER: Security issues in several third party TYPO3 extensions including sr_feuser_register
Several vulnerabilities have been found in the following third party TYPO3 extensions: "Frontend User Registration" (sr_feuser_register), "A21glossary Advanced Output" (a21glossary_advanced_output), "ClickStream Analyzer (output)" (alternet_csa_out), "Directory Listing" (dir_listing), "Store Locator" (locator), "Userdata Create/Edit" (sg_userdata), "Versatile Calendar Extension (VCE)" (sk_calendar), "ultraCards" (th_ultracards), "Visitor Tracking" (ws_stats).
TYPO3-SA-2009-003: Multiple vulnerabilities in TYPO3 third party extensions
Several vulnerabilities have been found in the following third party TYPO3 extensions: "Accessibility Glossary" (a21glossary), "Calendar Base" (cal), "Flat Manager" (flatmgr)
SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS-CONTAIN-SECURITY-ISSUES: Several third party TYPO3 extensions contain security issues
Vulnerabilities have been found in the following third party TYPO3 extensions: "Accessibility Glossary" (a21glossary), "Calendar Base" (cal), "Flat Manager" (flatmgr)
TYPO3-SA-2009-002: Information Disclosure & XSS in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to Information Disclosure and Cross-Site Scripting.
INFORMATION-DISCLOSURE-XSS-IN-TYPO3-CORE: Information Disclosure & XSS in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to Information Disclosure and Cross-Site Scripting.
IMPORTANT-SECURITY-BULLETIN-PRE-ANNOUNCEMENT: Important Security-Bulletin Pre-Announcement
Serious security issue found in TYPO3 core.
TYPO3-SA-2009-015: XSS and SQL injection vulnerabilities in extension "phpMyAdmin" (phpmyadmin)
It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to XSS and SQL injections.
MULTIPLE-SECURITY-ISSUES-FOUND-IN-TYPO3-CORE: Multiple security issues found in TYPO3 core
It has been discovered that TYPO3 Core is vulnerable to Broken Authentication and Session Management, Cross-Site Scripting, Insecure Randomness and Remote Command Execution.
TYPO3-SA-2009-001: Multiple vulnerabilities in TYPO3 Core
It has been discovered that TYPO3 Core is vulnerable to Broken Authentication and Session Management, Cross-Site Scripting, Insecure Randomness and Remote Command Execution.
SECURITY-ISSUES-IN-SEVERAL-THIRD-PARTY-TYPO3-EXTENSIONS: Security issues in several third party TYPO3 extensions
Security vulnerabilities have been discovered in the following third party TYPO3 extensions: "phpMyAdmin" (phpmyadmin), "DR Wiki - Typo3 Wiki extension" (dr_wiki), "WEC Discussion Forum" (wec_discussion), "Vox populi" (mv_vox_populi), "SB Universal Plugin" (SBuniplug), "Simple File Browser" (simplefilebrowser), "TU-Clausthal ODIN" (tuc_odin), "TU-Clausthal Staff" (tuc_staff), "WEBERkommunal Facilities" (wes_facilities).