Security advisories, releases and news from the TYPO3 ecosystem
- In focus — Picked as one of the six most noteworthy entries of the week and shown in the slider at the top.SecuritySeverity unknown
- In focus — Picked as one of the six most noteworthy entries of the week and shown in the slider at the top.SecuritySeverity unknown
TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)
- In focus — Picked as one of the six most noteworthy entries of the week and shown in the slider at the top.SecuritySeverity unknown
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
- In focus — Picked as one of the six most noteworthy entries of the week and shown in the slider at the top.SecuritySeverity unknown
TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)
- In focus — Picked as one of the six most noteworthy entries of the week and shown in the slider at the top.SecuritySeverity unknown
TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-022: Server-Side Template Injection (SSTI) in extension "powermail" (powermail)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-020: Broken Access Control in extension "Industry Directory" (yellowpages2)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-019: Broken Access Control in extension "Club Directory" (clubdirectory)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-018: Broken Access Control in extension "Telephone Directory" (telephonedirectory)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-017: Path Traversal in extension "Mask" (mask)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-016: Information Disclosure in extension "Modules" (modules)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-015: Multiple Vulnerabilities in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
- SecuritySeverity unknown
TYPO3-EXT-SA-2026-014: Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
- SecuritySeverity unknown
TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
- SecuritySeverity unknown
TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework
- SecurityHigh
TYPO3-CORE-SA-2026-019: Broken Access Control in Form Framework
- SecurityMedium
TYPO3-CORE-SA-2026-018: Insecure Deserialization in Core API
- SecurityHigh
TYPO3-CORE-SA-2026-017: Privilege Escalation & SQL Injection in Form Framework
- SecurityLow
TYPO3-CORE-SA-2026-016: Broken Access Control in File Abstraction Layer
- SecurityMedium
TYPO3-CORE-SA-2026-015: Broken Access Control in Backend API
- SecurityMedium
TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard
- SecurityHigh
TYPO3-CORE-SA-2026-013: Broken Access Control in Media Module
- SecurityMedium
TYPO3-CORE-SA-2026-012: Broken Access Control in DataHandler
- SecurityMedium
TYPO3-CORE-SA-2026-011: Broken Access Control in Recycler
- SecurityMedium
TYPO3-CORE-SA-2026-010: Cross-Site Scripting in Indexed Search
- SecurityMedium
TYPO3-CORE-SA-2026-009: Open Redirect in TYPO3 CMS
- SecurityHigh
TYPO3-CORE-SA-2026-008: Broken Access Control in Form Framework
- SecurityHigh
TYPO3-CORE-SA-2026-007: Broken Access Control in File Abstraction Layer
- SecurityMedium
TYPO3-CORE-SA-2026-006: By-passing Cross-Site Scripting Protection in HTML Sanitizer