TYPO3-EXT-SA-2020-015: Cross-Site Scripting in extension "Kitodo.Presentation" (dlf)
- Release Date: July 29, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3 10.4.6 and 9.5.20 security releases published
The following TYPO3 updates have been released:
- TYPO3 10.4.6 LTS
- TYPO3 9.5.20 LTS
Both versions are security releases and contain important…
TYPO3-CORE-SA-2020-008: Sensitive Information Disclosure
- Component Type: TYPO3 CMS
- Subcomponent: Backend User Interface (ext:backend)
- Release Date: July 28, 2020
- Vulnerability Type:…
TYPO3-CORE-SA-2020-007: Potential Privilege Escalation
- Component Type: TYPO3 CMS
- Subcomponent: eID API (ext:frontend, ext:core)
- Release Date: July 28, 2020
- Vulnerability Type: Privilege…
TYPO3-EXT-SA-2020-014: Sensitive Information Disclosure in extension "Media Content Element" (mediace)
- Release Date: July 28, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- …
TYPO3-PSA-2020-001: Critical vulnerability in legacy versions of TYPO3 CMS
TYPO3-EXT-SA-2020-014 addresses the same vulnerability - the functionality has been extracted back then during TYPO3 v7 development to extension …
Structured Content Initiative—What Happened in May–June 2020?
The Structured Content Initiative is the core Strategic Initiative focused on improving the content editing user experience in TYPO3 CMS. Read our…
Report from the typo3.org Team 2020—Part 1
Team Sprints / Remote Days
Like all of the TYPO3 teams and nearly the whole of humanity, we also faced the problem named COVID-19. Just before the…
TYPO3-EXT-SA-2020-013: Multiple vulnerabilities in extension "mm_forum" (mm_forum)
- Release Date: July 07, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Component:…
TYPO3-EXT-SA-2020-012: Cross-Site Scripting in extension "Google reCAPTCHA (v2/v3)" (jh_captcha)
- Release Date: July 07, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Component:…
TYPO3-EXT-SA-2020-011: Remote Code Execution in extension "Turn!" (turn)
- Release Date: July 07, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Component:…
TYPO3-EXT-SA-2020-010: Broken Access Control in extension "typo3_forum" (typo3_forum)
- Release Date: July 07, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Component:…
TYPO3 10.4.5 maintenance release published
The following TYPO3 update has been released:
- TYPO3 10.4.5 LTS
This version is a maintenance release only.
Further upgrade instructions
No database…
TYPO3-EXT-SA-2020-009: Cross-Site Scripting in extension "Faceted Search" (ke_search)
- Release Date: July 07, 2020
- Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.
- Component:…