piwik
Header Background

TYPO3 News

TYPO3-News

Direct Contact

Let us talk about your next project.

+49 40 4327 3227

TYPO3 Sicherheitsmeldungen

TYPO3.org

TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands

TYPO3.org
It has been discovered that TYPO3 CMS is susceptible to unauthorized modification of system-wide configuration.

TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard

TYPO3.org
It has been discovered that TYPO3 CMS is susceptible to information disclosure.

TYPO3-EXT-SA-2026-027: SQL Injection in extension "Forms Export" (frp_form_answers)

TYPO3.org
It has been discovered that the extension "Forms Export" (frp_form_answers) is vulnerable to SQL Injection.

TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)

TYPO3.org
It has been discovered that the extension "Events 2" (events2) is susceptible to two instances of Broken Access Control.

TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

TYPO3.org
It has been discovered that the extension "Apache Solr for TYPO3 - Enterprise Search" (solr) is vulnerable to Broken Access Control, Insecure Deserialization and Information Disclosure.

TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)

TYPO3.org
It has been discovered that the extension "femanager" (femanager) is vulnerable to Broken Access Control and Information Disclosure.

TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)

TYPO3.org
It has been discovered that the extension "Event management and registration" (sf_event_mgt) is vulnerable to Broken Access Control and Server-Side Template Injection (SSTI).

TYPO3-EXT-SA-2026-022: Server-Side Template Injection (SSTI) in extension "powermail" (powermail)

TYPO3.org
It has been discovered that the extension "powermail" (powermail) is vulnerable to Server-Side Template Injection (SSTI).

TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum)

TYPO3.org
It has been discovered that the extension "Forum" (pforum) is susceptible to Broken Access Control.

TYPO3-EXT-SA-2026-020: Broken Access Control in extension "Industry Directory" (yellowpages2)

TYPO3.org
It has been discovered that the extension "Industry Directory" (yellowpages2) is susceptible to Broken Access Control.

TYPO3-EXT-SA-2026-019: Broken Access Control in extension "Club Directory" (clubdirectory)

TYPO3.org
It has been discovered that the extension "Club Directory" (clubdirectory) is susceptible to Broken Access Control.

TYPO3-EXT-SA-2026-018: Broken Access Control in extension "Telephone Directory" (telephonedirectory)

TYPO3.org
It has been discovered that the extension "Telephone Directory" (telephonedirectory) is susceptible to Broken Access Control.

TYPO3-EXT-SA-2026-017: Path Traversal in extension "Mask" (mask)

TYPO3.org
It has been discovered that the extension "Mask" (mask) is vulnerable to Path Traversal.

TYPO3-EXT-SA-2026-016: Information Disclosure in extension "Modules" (modules)

TYPO3.org
It has been discovered that the extension "Modules" (modules) is vulnerable to Information Disclosure.

TYPO3-EXT-SA-2026-015: Multiple Vulnerabilities in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)

TYPO3.org
It has been discovered that the extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy) is vulnerable to Insufficient Session Expiration and Cleartext Transmission of Sensitive Information.

TYPO3-EXT-SA-2026-014: Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)

TYPO3.org
It has been discovered that the extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) is vulnerable to Remote Code Execution.

TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool

TYPO3.org
It has been discovered that TYPO3 CMS is susceptible to broken access control.

TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework

TYPO3.org
It has been discovered that TYPO3 CMS is susceptible to security misconfiguration.