TYPO3 Logo
  • TYPO3 CMS
    • Features
      • Smart Content Management
      • Secure Performant Scalable
      • Universal Frontend User Experience
      • Professional Open Source
      • Open Extensible Customizable
      • Digital Marketing Enabled
      • Massively Multisite Multilingual
    • Development Roadmap
      • TYPO3 Development Roadmap
      • Maintenance Releases Schedule
    • Strategy
    • Core Development
    • Release News
      • TYPO3 11 Release Notes
      • TYPO3 10 Release Notes
      • TYPO3 9 Release Notes
      • TYPO3 8 Release Notes
      • TYPO3 7 Release Notes
    • Documentation
    • Comparison Cards
    • System Requirements
    • Download & Install
    • Getting Started
    • Fluid Template Engine
  • Community
    • Events
    • Meet the Community
      • Communicate: Where and how
      • User Groups
      • StackOverflow
      • Forum
      • Chat (Slack)
      • how to use Slack
      • Regular Open Sprints
      • You, me, and TYPO3!
    • Contribute / Get Involved
      • TYPO3 remote days
      • Become an Association Member
      • Get your My TYPO3 account
      • Donate
      • Mentorship
      • Community Writers Program
    • Teams & Committees
      • TYPO3 Development
      • Academic
      • Accessibility
      • Best Practices
      • Communication Coordination
      • Community Expansion
      • Content
      • Content Types
      • Documentation
      • Education & Certification
      • Localization
      • Marketing
      • Ombudsperson
      • Security
      • Server
      • TYPO3 CMS Product Strategy Group
      • typo3.org website
      • User Experience (UX)
    • Values and Proceedings
      • Code of Conduct
      • Community Mediation
      • Conflict of Interest Policy
      • Social Media Guidelines
      • Decision-Making Processes, Contribution and Participation
      • Open Web Manifesto
      • Policy for Committees & Official Teams
      • Usage of Titles
      • Vision, Mission, Purpose
    • Team Leader Meetings
    • Data Protection Corner
      • Training for the TYPO3 teams
    • Services
      • e-mail-addresses
  • The Project
    • News
      • RSS feed
      • Security Advisories
      • This Month in TYPO3
      • Podcast
    • Our Products
    • TYPO3 Association
      • Become a Member
      • Our Members
      • Structure
      • Association News
      • Partnerships
      • Funding & Finances
      • General Assembly
      • By-Laws & proceedings
      • Contact
      • Association Strategy
    • The Brand
      • Trademarks
      • Style Guide
      • TYPO3 slidedeck
      • Spelling TYPO3
    • History
    • Press
      • Press Releases
      • TYPO3 v9 Release Material
      • TYPO3 v10 Release Material
      • TYPO3 v11 Release Material
      • TYPO3 v12 Release Material
      • TYPO3 v13 Release Material
    • Licenses
    • Technology Supporters
  • Certification
  • Help & Support
    • Documentation
      • Getting Started
      • Video Tutorials
      • What's New
    • Security Advisories
      • TYPO3 CMS
      • TYPO3 Extensions
      • Public Service Announcements
      • Security Advisories (RSS Feed)
    • Professional Services
    • Official TYPO3 Forum
    • TYPO3 LTS Extended Support
    • Stack Overflow
  • Search
  • Login
  • Overview
  • Features +
  • Development Roadmap +
  • Strategy
  • Core Development
  • Release News +
  • Documentation
  • Comparison Cards
  • System Requirements
  • Download & Install
  • Getting Started
  • Fluid Template Engine
  • Smart Content Management
  • Secure Performant Scalable
  • Universal Frontend User Experience
  • Professional Open Source
  • Open Extensible Customizable
  • Digital Marketing Enabled
  • Massively Multisite Multilingual
  • TYPO3 Development Roadmap
  • Maintenance Releases Schedule
  • TYPO3 11 Release Notes
  • TYPO3 10 Release Notes
  • TYPO3 9 Release Notes
  • TYPO3 8 Release Notes
  • TYPO3 7 Release Notes

Professional Content Management

Free and open source, TYPO3 CMS is the most widely used enterprise-level CMS.

Test TYPO3 now:

TYPO3 live demo
  • TYPO3 Community
  • Events
  • Meet the Community +
  • Contribute / Get Involved +
  • Teams & Committees +
  • Values and Proceedings +
  • Team Leader Meetings
  • Data Protection Corner +
  • Services +
  • Communicate: Where and how
  • User Groups
  • StackOverflow
  • Forum
  • Chat (Slack)
  • how to use Slack
  • Regular Open Sprints
  • You, me, and TYPO3!
  • TYPO3 remote days
  • Become an Association Member
  • Get your My TYPO3 account
  • Donate
  • Mentorship
  • Community Writers Program
  • TYPO3 Development
  • Academic
  • Accessibility
  • Best Practices
  • Communication Coordination
  • Community Expansion
  • Content
  • Content Types
  • Documentation
  • Education & Certification
  • Localization
  • Marketing
  • Ombudsperson
  • Security
  • Server
  • TYPO3 CMS Product Strategy Group
  • typo3.org website
  • User Experience (UX)
  • Code of Conduct
  • Community Mediation
  • Conflict of Interest Policy
  • Social Media Guidelines
  • Decision-Making Processes, Contribution and Participation
  • Open Web Manifesto
  • Policy for Committees & Official Teams
  • Usage of Titles
  • Vision, Mission, Purpose
  • Training for the TYPO3 teams
  • e-mail-addresses

Inspire people to share

Offer your skills and contribute to the project. The community is growing and does more than just coding. 

  • The TYPO3 Project
  • News +
  • Our Products
  • TYPO3 Association +
  • The Brand +
  • History
  • Press +
  • Licenses
  • Technology Supporters
  • RSS feed
  • Security Advisories
  • This Month in TYPO3
  • Podcast
  • Become a Member
  • Our Members
  • Structure
  • Association News
  • Partnerships
  • Funding & Finances
  • General Assembly
  • By-Laws & proceedings
  • Contact
  • Association Strategy
  • Trademarks
  • Style Guide
  • TYPO3 slidedeck
  • Spelling TYPO3
  • Press Releases
  • TYPO3 v9 Release Material
  • TYPO3 v10 Release Material
  • TYPO3 v11 Release Material
  • TYPO3 v12 Release Material
  • TYPO3 v13 Release Material

A Community Effort

TYPO3 CMS is an Open Source project managed by the TYPO3 Association.

The Project
  • Getting Help & Support
  • Documentation +
  • Security Advisories +
  • Professional Services
  • Official TYPO3 Forum
  • TYPO3 LTS Extended Support
  • Stack Overflow
  • Getting Started
  • Video Tutorials
  • What's New
  • TYPO3 CMS
  • TYPO3 Extensions
  • Public Service Announcements
  • Security Advisories (RSS Feed)

Do you have a question?

Ask the community or a professional partner.

Sort by
  • Relevance
  • Title
  • Creation Date
  • All 5056
  • News 2465
  • Extensions 1919
  • Composer packages 347
  • Pages 306
  • Events 19
  1. Security Bulletin TYPO3-20050812-1

    Component Type: Extension Affected Component: cc_awstats (and possibly others) Version: 0.9.0 and earlier Vulnerability Type: Remote Exploit Severity: Medium Problem Description: Remote exploitation…

    Published: 12th August 2005 by Karsten Dambekalns
  2. Security Bulletin TYPO3-20050822-1

    Published: 12th August 2005 by Karsten Dambekalns
  3. Security Bulletin TYPO3-20051010-1: fe_news

    A fix is available for fe_rtenews, while fe_news has been removed from the TER. Please see the complete Bulletin for details.

    Published: 10th October 2005 by Ekkehard Gümbel
  4. Security Bulletin TYPO3-20060501-1: chc_forum

    Component Type: Third Party Extension. The extension is not part of the TYPO3 default installation Affected Components: chc_forum Versions: 1.4.4 and earlier Vulnerability Type: SQL injection…

    Published: 2nd May 2006 by Michael Hirdes
  5. Security Bulletin TYPO3-20060902-1: tip-a-friend

    Component Type: Third Party Extension. The extension is not part of the TYPO3 default installation Affected Components: tipafriend Versions: 1.2.1 and earlier Vulnerability Type: Cross Site Scripting…

    Published: 2nd September 2006 by Michael Hirdes
  6. Security Bulletin TYPO3-20060911-1: indexed search

    Component Type: System Extension This Extension is Part of the TYPO3 default installation Affected Components: Indexed Search Versions: 2.9.0 under TYPO3 4.x Vulnerability Type: Cross Site Scripting…

    Published: 11th September 2006 by Michael Hirdes
  7. Security Bulletin TYPO3-20061010-1: fe_adminLib.inc

    Affected Versions: ALL Vulnerability Type: cross Site Scripting (XSS) Severity: minor Problem Description: The "backURL" parameter is not escaped correctly. A prepared URL could potentially contain…

    Published: 10th October 2006 by Michael Hirdes
  8. Security Bulletin TYPO3-20080416-1: Multiple vulnerabilities in extension de_phpot

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080416-1: Multiple vulnerabilities in extension de_phpot We also recommend that you subscribe to the TYPO3 Announce List ,…

    Published: 16th April 2008 by Henning Pingel
  9. Security Bulletin TYPO3-20080416-2: SQL Injections in extensions pmk_rssnewsexport and cm_rdfexport

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080416-2: SQL Injections in extensions pmk_rssnewsexport and cm_rdfexport We also recommend that you subscribe to the TYPO3…

    Published: 16th April 2008 by Henning Pingel
  10. Security Bulletin TYPO3-20080505-1: Multiple vulnerabilities in extension MailformPlus (th_mailformplus)

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080505-1: Multiple vulnerabilities in extension MailformPlus (th_mailformplus) We also recommend that you subscribe to the…

    Published: 5th May 2008 by Henning Pingel
  11. Security Bulletin TYPO3-20080505-2: Cross Site Scripting vulnerability in extension powermail

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080505-2: Cross Site Scripting vulnerability in extension powermail We also recommend that you subscribe to the TYPO3 Announce…

    Published: 5th May 2008 by Henning Pingel
  12. Security Bulletin TYPO3-20080513-1: Multiple vulnerabilities in extension WT Gallery (wt_gallery)

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080513-1: Multiple vulnerabilities in extension WT Gallery (wt_gallery) We also recommend that you subscribe to the TYPO3…

    Published: 13th May 2008 by Henning Pingel
  13. Security Bulletin TYPO3-20080513-2: Cross Site Scripting vulnerability in extension Questionaire (pbsurvey)

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080513-2: Cross Site Scripting vulnerability in extension Questionaire (pbsurvey) We also recommend that you subscribe to the…

    Published: 13th May 2008 by Henning Pingel
  14. Security Bulletin TYPO3-20080513-4: Multiple vulnerabilities in extension Statistics (ke_stats)

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080513-4: Multiple vulnerabilities in extension Statistics (ke_stats) We also recommend that you subscribe to the TYPO3…

    Published: 13th May 2008 by Henning Pingel
  15. Security Bulletin TYPO3-20080515-1: Multiple vulnerabilities in extension Frontend User Registration (sr_feuser_register)

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080515-1: Multiple vulnerabilities in extension Frontend User Registration (sr_feuser_register) We also recommend that you…

    Published: 15th May 2008 by Henning Pingel
  16. Security Bulletin TYPO3-20080515-2: Multiple vulnerabilities in extension Frontend Filemanager (air_filemanager)

    Please read the entire security bulletin here: Security Bulletin TYPO3-20080515-2: Multiple vulnerabilities in extension Frontend Filemanager (air_filemanager) We also recommend that you subscribe to…

    Published: 15th May 2008 by Henning Pingel
  17. Security Bulletin TYPO3-20080527-1: Cross Site Scripting vulnerability in extension "KJ: Image Lightbox v2" (kj_imagelightbox2)

    Please read the entire Security Bulletin here: Security Bulletin TYPO3-20080527-1: Cross Site Scripting vulnerability in extension "KJ: Image Lightbox v2" (kj_imagelightbox2) We also recommend that…

    Published: 27th May 2008 by Henning Pingel
  18. Security Bulletin TYPO3-20080527-2: SQL Injection in extension "Library for Frontend plugins" (sg_zfelib)

    Please read the entire Security Bulletin here: Security Bulletin TYPO3-20080527-2: SQL Injection in extension "Library for Frontend plugins" (sg_zfelib) We also recommend that you subscribe to the…

    Published: 27th May 2008 by Henning Pingel
  19. Security Bulletin TYPO3-20080611-1: Multiple vulnerabilities in TYPO3 Core

    Please read the entire Security Bulletin here: Security Bulletin TYPO3-20080611-1: Multiple vulnerabilities in TYPO3 Core We also recommend that you subscribe to the TYPO3 Announce List to receive all…

    Published: 11th June 2008 by Lars Houmark
  20. Security Bulletin TYPO3-20080619-1: Several vulnerabilities have been found in TYPO3 third party extensions

    This Collective Security Bulletin (CSB) is a listing of vulnerable extensions with neither significant download numbers nor other special importance amongst the TYPO3 Community. The intention of CSBs…

    Published: 19th June 2008 by Lars Houmark
  21. Security Bulletin TYPO3-20080916-1: Code execution vulnerability in extension phpMyAdmin

    Please read the entire Security Bulletin here: TYPO3 Security Bulletin TYPO3-20080916-1: Code execution vulnerability in extension phpMyAdmin (phpmyadmin) We also recommend that you subscribe to the…

    Published: 16th September 2008 by Lars Houmark
  22. Security Bulletin TYPO3-20080919-1: Multiple third party extensions found insecure

    Please follow the below link in order to read the entire security bulletin covering all 11 extensions. TYPO3-20080919-1: Collective Security Bulletin covering issues in 11 third party extensions:…

    Published: 19th September 2008 by Lars Houmark
  23. Security Bulletins: Important Security Enhancements in TYPO3 3.8.1

    Over the years, TYPO3 has become very mature in many respects, one of which is the seriousness that is being put on security matters. Therefore the current release 3.8.1 contains some improvements as…

    Published: 14th November 2005 by Ekkehard Gümbel
  24. Security Bulletins: chc_forum, th_mailformplus

    TYPO3-20051107-1 : A bug has been discovered in the "CHC Forum" (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms. Thus, specially crafted entries…

    Published: 7th November 2005 by Ekkehard Gümbel
  25. Security Bypass Vulnerability in extension powermail (powermail)

    Release Date: June 03, 2013 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 1.6.9 and below, 2.0.1 - 2.0.6…

    Published: 3rd June 2013 by Franz G. Jahn
    • «
    • ‹
    • ....
    • 104
    • 105
    • 106
    • 107
    • 108
    • 109
    • 110
    • 111
    • 112
    • 113
    • ....
    • ›
    • »
Ready to get started?
Download TYPO3 CMS for free!
Download Get more info
TYPO3
🦋
Logo with a blue badge and white checkmark next to the letters DPG on a dark blue background.  White geometric cubes and bold text on an orange background represent 9 Industry, Innovation and Infrastructure, which is one of the United Nations Sustainable Development Goals.  A white equal sign surrounded by four arrows pointing outward on a pink background represent 9 reduced inequalities, which is one of the United Nations Sustainable Development Goals.
© 2025 TYPO3 Association

Information

  • Decision makers
  • Users
  • Developers
  • Contact form

Downloads

  • TYPO3 CMS
  • Extensions for TYPO3

Community

  • my.typo3.org
  • Slack for TYPO3 community
  • TYPO3 Code of Conduct

Popular links

  • Legal Notice
  • TYPO3.com
  • TYPO3 Association
  • Privacy Policy
  • Social Media Privacy Policy