<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 security advisories</title>
        <description>Recent posts</description>
        <language>en</language>
        <link>https://news.typo3.com/security/rss-security</link>
        <lastBuildDate>Wed, 09 Sep 2026 13:41:37 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-023</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-023#comments</comments><pubDate>Tue, 08 Sep 2026 11:01:00 +0200</pubDate><dc:creator>Elias Häußler</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-023</guid><description>It has been discovered that TYPO3 CMS is susceptible to unauthorized modification of system-wide configuration.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-022</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-022#comments</comments><pubDate>Tue, 08 Sep 2026 11:00:00 +0200</pubDate><dc:creator>Elias Häußler</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-022</guid><description>It has been discovered that TYPO3 CMS is susceptible to information disclosure.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-027: SQL Injection in extension &quot;Forms Export&quot; (frp_form_answers)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-027</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-027#comments</comments><pubDate>Tue, 25 Aug 2026 10:14:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-027</guid><description>It has been discovered that the extension &quot;Forms Export&quot; (frp_form_answers) is vulnerable to SQL Injection.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-026: Broken Access Control in extension &quot;Events 2&quot; (events2)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-026</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-026#comments</comments><pubDate>Tue, 25 Aug 2026 10:13:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-026</guid><description>It has been discovered that the extension &quot;Events 2&quot; (events2) is susceptible to two instances of Broken Access Control.
</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension &quot;Apache Solr for TYPO3 - Enterprise Search&quot; (solr)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025#comments</comments><pubDate>Tue, 25 Aug 2026 10:12:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025</guid><description>It has been discovered that the extension &quot;Apache Solr for TYPO3 - Enterprise Search&quot; (solr) is vulnerable to Broken Access Control, Insecure Deserialization and Information Disclosure.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension &quot;femanager&quot; (femanager)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-024</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-024#comments</comments><pubDate>Tue, 25 Aug 2026 10:11:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-024</guid><description>It has been discovered that the extension &quot;femanager&quot; (femanager) is vulnerable to Broken Access Control and Information Disclosure.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension &quot;Event management and registration&quot; (sf_event_mgt)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023#comments</comments><pubDate>Tue, 25 Aug 2026 10:10:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023</guid><description>It has been discovered that the extension &quot;Event management and registration&quot; (sf_event_mgt) is vulnerable to Broken Access Control and Server-Side Template Injection (SSTI).</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-022: Server-Side Template Injection (SSTI) in extension &quot;powermail&quot; (powermail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-022</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-022#comments</comments><pubDate>Tue, 25 Aug 2026 10:09:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-022</guid><description>It has been discovered that the extension &quot;powermail&quot; (powermail) is vulnerable to Server-Side Template Injection (SSTI).</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-021: Broken Access Control in extension &quot;Forum&quot; (pforum)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021#comments</comments><pubDate>Tue, 25 Aug 2026 10:08:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021</guid><description>It has been discovered that the extension &quot;Forum&quot; (pforum) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-020: Broken Access Control in extension &quot;Industry Directory&quot; (yellowpages2)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-020</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-020#comments</comments><pubDate>Tue, 25 Aug 2026 10:07:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-020</guid><description>It has been discovered that the extension &quot;Industry Directory&quot; (yellowpages2) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-019: Broken Access Control in extension &quot;Club Directory&quot; (clubdirectory)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-019</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-019#comments</comments><pubDate>Tue, 25 Aug 2026 10:06:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-019</guid><description>It has been discovered that the extension &quot;Club Directory&quot; (clubdirectory) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-018: Broken Access Control in extension &quot;Telephone Directory&quot; (telephonedirectory)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-018</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-018#comments</comments><pubDate>Tue, 25 Aug 2026 10:05:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-018</guid><description>It has been discovered that the extension &quot;Telephone Directory&quot; (telephonedirectory) is susceptible to Broken Access Control.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-017: Path Traversal in extension &quot;Mask&quot; (mask)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-017</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-017#comments</comments><pubDate>Tue, 25 Aug 2026 10:04:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-017</guid><description>It has been discovered that the extension &quot;Mask&quot; (mask) is vulnerable to Path Traversal.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-016: Information Disclosure in extension &quot;Modules&quot; (modules)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-016</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-016#comments</comments><pubDate>Tue, 25 Aug 2026 10:03:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-016</guid><description>It has been discovered that the extension &quot;Modules&quot; (modules) is vulnerable to Information Disclosure.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-015: Multiple Vulnerabilities in extension &quot;SYSSY - TYPO3 Monitoring &amp; Security Checks&quot; (syssy)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-015</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-015#comments</comments><pubDate>Tue, 25 Aug 2026 10:02:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-015</guid><description>It has been discovered that the extension &quot;SYSSY - TYPO3 Monitoring &amp; Security Checks&quot; (syssy) is vulnerable to Insufficient Session Expiration and Cleartext Transmission of Sensitive Information.</description></item>


    
        
<item><title>TYPO3-EXT-SA-2026-014: Remote Code Execution in extension &quot;HTML5 Video Player vs. Powermail&quot; (html5videoplayer_powermail)</title><link>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-014</link><comments>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-014#comments</comments><pubDate>Tue, 25 Aug 2026 10:01:00 +0200</pubDate><dc:creator>Torben Hansen</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-ext-sa-2026-014</guid><description>It has been discovered that the extension &quot;HTML5 Video Player vs. Powermail&quot; (html5videoplayer_powermail) is vulnerable to Remote Code Execution.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-021</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-021#comments</comments><pubDate>Tue, 11 Aug 2026 09:30:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-021</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-020</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-020#comments</comments><pubDate>Tue, 14 Jul 2026 12:00:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-020</guid><description>It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-019: Broken Access Control in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-019</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-019#comments</comments><pubDate>Tue, 09 Jun 2026 12:19:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-019</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-018: Insecure Deserialization in Core API</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-018</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-018#comments</comments><pubDate>Tue, 09 Jun 2026 12:18:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-018</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-017: Privilege Escalation &amp; SQL Injection in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-017</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-017#comments</comments><pubDate>Tue, 09 Jun 2026 12:17:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-017</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-016: Broken Access Control in File Abstraction Layer</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-016</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-016#comments</comments><pubDate>Tue, 09 Jun 2026 12:16:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-016</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-015: Broken Access Control in Backend API</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-015</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-015#comments</comments><pubDate>Tue, 09 Jun 2026 12:15:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-015</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-014</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-014#comments</comments><pubDate>Tue, 09 Jun 2026 12:14:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-014</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-013: Broken Access Control in Media Module</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-013</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-013#comments</comments><pubDate>Tue, 09 Jun 2026 12:13:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-013</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-012: Broken Access Control in DataHandler</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-012</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-012#comments</comments><pubDate>Tue, 09 Jun 2026 12:12:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-012</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-011: Broken Access Control in Recycler</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-011</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-011#comments</comments><pubDate>Tue, 09 Jun 2026 12:11:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-011</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-010: Cross-Site Scripting in Indexed Search</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-010</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-010#comments</comments><pubDate>Tue, 09 Jun 2026 12:10:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-010</guid><description>It has been discovered that TYPO3 CMS is vulnerable to cross-site scripting.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-009: Open Redirect in TYPO3 CMS</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-009</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-009#comments</comments><pubDate>Tue, 09 Jun 2026 12:09:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-009</guid><description>It has been discovered that TYPO3 CMS is susceptible to open redirect.</description></item>


    
        
<item><title>TYPO3-CORE-SA-2026-008: Broken Access Control in Form Framework</title><link>https://news.typo3.com/security/advisory/typo3-core-sa-2026-008</link><comments>https://news.typo3.com/security/advisory/typo3-core-sa-2026-008#comments</comments><pubDate>Tue, 09 Jun 2026 12:08:00 +0200</pubDate><dc:creator>Oliver Hader</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-core-sa-2026-008</guid><description>It has been discovered that TYPO3 CMS is susceptible to broken access control.</description></item>


    



    </channel>
</rss>
