Security advisories, releases and news from the TYPO3 ecosystem
In focus
- 1SecuritySeverity unknown
TYPO3-EXT-SA-2026-027: SQL Injection in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) is vulnerable to SQL Injection.
TYPO3 Security Advisories
- 2SecuritySeverity unknown
TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)
It has been discovered that the extension "Events 2" (events2) is susceptible to two instances of Broken Access Control.
TYPO3 Security Advisories
- 3SecuritySeverity unknown
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
It has been discovered that the extension "Apache Solr for TYPO3 - Enterprise Search" (solr) is vulnerable to Broken Access Control, Insecure Deserialization and Information Disclosure.
TYPO3 Security Advisories
- 4SecuritySeverity unknown
TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is vulnerable to Broken Access Control and Information Disclosure.
TYPO3 Security Advisories
- 5SecuritySeverity unknown
TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
It has been discovered that the extension "Event management and registration" (sf_event_mgt) is vulnerable to Broken Access Control and Server-Side Template Injection (SSTI).
TYPO3 Security Advisories
- 6Official
Content Blocks: Q2/2026 Report and the GUI for TYPO3 v14
AI summaryThe Content Blocks GUI now operates on TYPO3 v13 and v14 from a unified codebase, with enhancements made to the JSON Schema, and a team member participated in the TYPO3 Dialogue Days in Düsseldorf.
TYPO3 News
- 1SecuritySeverity unknown
TYPO3-EXT-SA-2026-027: SQL Injection in extension "Forms Export" (frp_form_answers)
It has been discovered that the extension "Forms Export" (frp_form_answers) is vulnerable to SQL Injection.
TYPO3 Security Advisories
- 2SecuritySeverity unknown
TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)
It has been discovered that the extension "Events 2" (events2) is susceptible to two instances of Broken Access Control.
TYPO3 Security Advisories
- 3SecuritySeverity unknown
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
It has been discovered that the extension "Apache Solr for TYPO3 - Enterprise Search" (solr) is vulnerable to Broken Access Control, Insecure Deserialization and Information Disclosure.
TYPO3 Security Advisories
- 4SecuritySeverity unknown
TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)
It has been discovered that the extension "femanager" (femanager) is vulnerable to Broken Access Control and Information Disclosure.
TYPO3 Security Advisories
- 5SecuritySeverity unknown
TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
It has been discovered that the extension "Event management and registration" (sf_event_mgt) is vulnerable to Broken Access Control and Server-Side Template Injection (SSTI).
TYPO3 Security Advisories
- 6Official
Content Blocks: Q2/2026 Report and the GUI for TYPO3 v14
AI summaryThe Content Blocks GUI now operates on TYPO3 v13 and v14 from a unified codebase, with enhancements made to the JSON Schema, and a team member participated in the TYPO3 Dialogue Days in Düsseldorf.
TYPO3 News
- Blog
- Blog
Panopto: Video Content Management trifft TYPO3
in2code
- Blog
TYPO3 Extbase-Bug „#1205414233: No suitable request handler found.“
CodeBlog.at
- Blog
Windows und TYPO3
CodeBlog.at