TYPO3 Logo
  • TYPO3 CMS
    • Features
      • Smart Content Management
      • Secure Performant Scalable
      • Universal Frontend User Experience
      • Professional Open Source
      • Open Extensible Customizable
      • Digital Marketing Enabled
      • Massively Multisite Multilingual
    • Development Roadmap
      • TYPO3 Development Roadmap
      • Maintenance Releases Schedule
    • Strategy
    • Core Development
    • Release News
      • TYPO3 11 Release Notes
      • TYPO3 10 Release Notes
      • TYPO3 9 Release Notes
      • TYPO3 8 Release Notes
      • TYPO3 7 Release Notes
    • Documentation
    • Comparison Cards
    • System Requirements
    • Download & Install
    • Getting Started
    • Fluid Template Engine
  • Community
    • Events
    • Meet the Community
      • Communicate: Where and how
      • User Groups
      • StackOverflow
      • Forum
      • Chat (Slack)
      • how to use Slack
      • Regular Open Sprints
      • You, me, and TYPO3!
    • Contribute / Get Involved
      • TYPO3 remote days
      • Become an Association Member
      • Get your My TYPO3 account
      • Donate
      • Mentorship
      • Community Writers Program
    • Teams & Committees
      • TYPO3 Development
      • Academic
      • Accessibility
      • Best Practices
      • Communication Coordination
      • Community Expansion
      • Content
      • Content Types
      • Documentation
      • Education & Certification
      • Localization
      • Marketing
      • Ombudsperson
      • Security
      • Server
      • TYPO3 CMS Product Strategy Group
      • typo3.org website
      • User Experience (UX)
    • Values and Proceedings
      • Code of Conduct
      • Community Mediation
      • Conflict of Interest Policy
      • Social Media Guidelines
      • Decision-Making Processes, Contribution and Participation
      • Open Web Manifesto
      • Policy for Committees & Official Teams
      • Usage of Titles
      • Vision, Mission, Purpose
    • Team Leader Meetings
    • Data Protection Corner
      • Training for the TYPO3 teams
    • Services
      • e-mail-addresses
  • The Project
    • News
      • RSS feed
      • Security Advisories
      • This Month in TYPO3
      • Podcast
    • Our Products
    • TYPO3 Association
      • Become a Member
      • Our Members
      • Structure
      • Association News
      • Partnerships
      • Funding & Finances
      • General Assembly
      • By-Laws & proceedings
      • Contact
      • Association Strategy
    • The Brand
      • Trademarks
      • Style Guide
      • TYPO3 slidedeck
      • Spelling TYPO3
    • History
    • Press
      • Press Releases
      • TYPO3 v9 Release Material
      • TYPO3 v10 Release Material
      • TYPO3 v11 Release Material
      • TYPO3 v12 Release Material
      • TYPO3 v13 Release Material
    • Licenses
    • Technology Supporters
  • Certification
  • Help & Support
    • Documentation
      • Getting Started
      • Video Tutorials
      • What's New
    • Security Advisories
      • TYPO3 CMS
      • TYPO3 Extensions
      • Public Service Announcements
      • Security Advisories (RSS Feed)
    • Professional Services
    • Official TYPO3 Forum
    • TYPO3 LTS Extended Support
    • Stack Overflow
  • Search
  • Login
  • Overview
  • Features +
  • Development Roadmap +
  • Strategy
  • Core Development
  • Release News +
  • Documentation
  • Comparison Cards
  • System Requirements
  • Download & Install
  • Getting Started
  • Fluid Template Engine
  • Smart Content Management
  • Secure Performant Scalable
  • Universal Frontend User Experience
  • Professional Open Source
  • Open Extensible Customizable
  • Digital Marketing Enabled
  • Massively Multisite Multilingual
  • TYPO3 Development Roadmap
  • Maintenance Releases Schedule
  • TYPO3 11 Release Notes
  • TYPO3 10 Release Notes
  • TYPO3 9 Release Notes
  • TYPO3 8 Release Notes
  • TYPO3 7 Release Notes

Professional Content Management

Free and open source, TYPO3 CMS is the most widely used enterprise-level CMS.

Test TYPO3 now:

TYPO3 live demo
  • TYPO3 Community
  • Events
  • Meet the Community +
  • Contribute / Get Involved +
  • Teams & Committees +
  • Values and Proceedings +
  • Team Leader Meetings
  • Data Protection Corner +
  • Services +
  • Communicate: Where and how
  • User Groups
  • StackOverflow
  • Forum
  • Chat (Slack)
  • how to use Slack
  • Regular Open Sprints
  • You, me, and TYPO3!
  • TYPO3 remote days
  • Become an Association Member
  • Get your My TYPO3 account
  • Donate
  • Mentorship
  • Community Writers Program
  • TYPO3 Development
  • Academic
  • Accessibility
  • Best Practices
  • Communication Coordination
  • Community Expansion
  • Content
  • Content Types
  • Documentation
  • Education & Certification
  • Localization
  • Marketing
  • Ombudsperson
  • Security
  • Server
  • TYPO3 CMS Product Strategy Group
  • typo3.org website
  • User Experience (UX)
  • Code of Conduct
  • Community Mediation
  • Conflict of Interest Policy
  • Social Media Guidelines
  • Decision-Making Processes, Contribution and Participation
  • Open Web Manifesto
  • Policy for Committees & Official Teams
  • Usage of Titles
  • Vision, Mission, Purpose
  • Training for the TYPO3 teams
  • e-mail-addresses

Inspire people to share

Offer your skills and contribute to the project. The community is growing and does more than just coding. 

  • The TYPO3 Project
  • News +
  • Our Products
  • TYPO3 Association +
  • The Brand +
  • History
  • Press +
  • Licenses
  • Technology Supporters
  • RSS feed
  • Security Advisories
  • This Month in TYPO3
  • Podcast
  • Become a Member
  • Our Members
  • Structure
  • Association News
  • Partnerships
  • Funding & Finances
  • General Assembly
  • By-Laws & proceedings
  • Contact
  • Association Strategy
  • Trademarks
  • Style Guide
  • TYPO3 slidedeck
  • Spelling TYPO3
  • Press Releases
  • TYPO3 v9 Release Material
  • TYPO3 v10 Release Material
  • TYPO3 v11 Release Material
  • TYPO3 v12 Release Material
  • TYPO3 v13 Release Material

A Community Effort

TYPO3 CMS is an Open Source project managed by the TYPO3 Association.

The Project
  • Getting Help & Support
  • Documentation +
  • Security Advisories +
  • Professional Services
  • Official TYPO3 Forum
  • TYPO3 LTS Extended Support
  • Stack Overflow
  • Getting Started
  • Video Tutorials
  • What's New
  • TYPO3 CMS
  • TYPO3 Extensions
  • Public Service Announcements
  • Security Advisories (RSS Feed)

Do you have a question?

Ask the community or a professional partner.

Sort by
  • Relevance
  • Title
  • Creation Date
  • All 5044
  • News 2456
  • Extensions 1918
  • Composer packages 345
  • Pages 306
  • Events 19
  1. Cross Site Scripting vulnerability in extension powermail

    Component Type: Third party extension. This extension is not part of the TYPO3 default installation. Affected Versions: Version 1.1.9 and all versions below Vulnerability Type: Cross Site Scripting…

    Published: 5th May 2008
  2. Cross Site Scripting vulnerability in faq

    Component Type: Third party extension. This extension is not part of the TYPO3 default installation Affected Versions: Version 0.0.7 and all versions below Vulnerability Type: Cross Site Scripting…

    Published: 16th July 2007
  3. Cross Site-Scripting in extension "CAB FAL search" (falsearch)

    Release Date: November 07, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 0.2.0 and below Vulnerability Type:…

    Published: 7th November 2017 by Torben Hansen
  4. Cross Site-Scripting in extension "Caretaker" (caretaker)

    Release Date: December 18, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 0.8.0 and below Vulnerability Type:…

    Published: 19th December 2017 by Nicole Cordes
  5. Cross Site-Scripting in extension "Formhandler" (formhandler)

    Release Date: November 07, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.4.0 and below Vulnerability Type:…

    Published: 7th November 2017 by Torben Hansen
  6. Cross Site-Scripting in extension "Multishop" (multishop)

    Release Date: November 07, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 5.0.0 and below Vulnerability Type:…

    Published: 7th November 2017 by Torben Hansen
  7. Cross Site-Scripting in extension "Recommend page " (pb_recommend_page)

    Release Date: November 07, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.0.3 and below Vulnerability Type:…

    Published: 7th November 2017 by Torben Hansen
  8. Cross Site-Scripting in extension "Secure Download Form" (rs_securedownload)

    Release Date: November 14, 2016 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 0.3.2 and below Vulnerability Type:…

    Published: 14th November 2016 by Nicole Cordes
  9. Cross Site-Scripting in extension "Smallads" (ke_smallads)

    Release Date: December 18, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.3.2 and below Vulnerability Type:…

    Published: 19th December 2017 by Nicole Cordes
  10. Cross Site-Scripting in extension "T3Blog Extbase" (t3extblog)

    Release Date: November 07, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.2.1 and below Vulnerability Type:…

    Published: 7th November 2017 by Torben Hansen
  11. Cross-Site Request Forgery Protection in TYPO3 CMS 6.2

    Component Type: TYPO3 CMS Vulnerability Types: Cross-Site Request Forgery (CSRF) Overall Severity: Low Release Date: January 31, 2014 Affected Versions: All versions below 6.2 CVE: Will be requested.…

    Published: 28th January 2014
  12. Cross-Site Request Forgery in Backend User Module

    Component Type: TYPO3 CMS Subcomponent: Backend User Module (ext:beuser) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41,…

    Published: 14th January 2025 by Oliver Hader
  13. Cross-Site Request Forgery in DB Check Module

    Component Type: TYPO3 CMS Subcomponent: DB Check Module (ext:lowlevel) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41 Severity: Medium…

    Published: 14th January 2025 by Oliver Hader
  14. Cross-Site Request Forgery in Dashboard Module

    Component Type: TYPO3 CMS Subcomponent: Dashboard Module (ext:dashboard) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41,…

    Published: 14th January 2025 by Oliver Hader
  15. Cross-Site Request Forgery in Extension Manager Module

    Component Type: TYPO3 CMS Subcomponent: Extension Manager (ext:extensionmanager) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41,…

    Published: 14th January 2025 by Oliver Hader
  16. Cross-Site Request Forgery in Form Framework Module

    Component Type: TYPO3 CMS Subcomponent: Form Framework (ext:form) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41, 12.0.0-12.4.24,…

    Published: 14th January 2025 by Oliver Hader
  17. Cross-Site Request Forgery in Indexed Search Module

    Component Type: TYPO3 CMS Subcomponent: Indexed Search (ext:indexed_search) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41,…

    Published: 14th January 2025 by Oliver Hader
  18. Cross-Site Request Forgery in Log Module

    Component Type: TYPO3 CMS Subcomponent: Log Module (ext:belog) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41, 12.0.0-12.4.24,…

    Published: 14th January 2025 by Oliver Hader
  19. Cross-Site Request Forgery in Scheduler Module

    Component Type: TYPO3 CMS Subcomponent: Scheduler (ext:scheduler) Release Date: January 14, 2025 Vulnerability Type: Cross-Site Request Forgery Affected Versions: 11.0.0-11.5.41 Severity: High…

    Published: 14th January 2025 by Oliver Hader
  20. Cross-Site Request Forgery in extension "Typo3 Quixplorer" (t3quixplorer)

    Release Date: September 30, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.7.2 and below Vulnerability Type:…

    Published: 30th September 2015 by Nicole Cordes
  21. Cross-Site Scripting Vulnerability in TYPO3 Core

    Component Type: TYPO3 Core Affected Versions: 4.4.0 up to 4.4.14, 4.5.0 up to 4.5.14, 4.6.0 up to 4.6.7 and development releases of the 4.7 branch. Vulnerable subcomponent: Exception Handler…

    Published: 17th April 2012 by Helmut Hummel
  22. Cross-Site Scripting and Open Redirection vulnerability in extension phpMyAdmin (phpmyadmin)

    Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 4.10.3 and below Vulnerability Type: Cross-Site Scripting, Open…

    Published: 23rd May 2011 by Marcus Krause
  23. Cross-Site Scripting and Remote Code Execution Vulnerability in TYPO3 Core

    Component Type: TYPO3 Core Vulnerability Types: Cross-Site Scripting, Remote Code Execution Overall Severity: Critical Release Date: July 30, 2013 Vulnerable subcomponent: Third Party Libraries used…

    Published: 30th July 2013 by Georg Ringer
  24. Cross-Site Scripting in "SVG Sanitizer" (svg_sanitizer)

    Release Date: May 12, 2020 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: SVG Sanitizer (ext:svg_sanitizer) Vulnerability Type:…

    Published: 12th May 2020 by Oliver Hader
  25. Cross-Site Scripting in 3rd party library Flowplayer

    Component Type: TYPO3 CMS Release Date: July 1, 2015 Vulnerable subcomponent: Frontend Media Rendering (ext:frontend, ext:mediace) Vulnerability Type: Cross-Site Scripting Affected Versions: Versions…

    Published: 1st July 2015 by Helmut Hummel
    • «
    • ‹
    • ....
    • 23
    • 24
    • 25
    • 26
    • 27
    • 28
    • 29
    • 30
    • 31
    • 32
    • ....
    • ›
    • »
Ready to get started?
Download TYPO3 CMS for free!
Download Get more info
TYPO3
🦋
Logo with a blue badge and white checkmark next to the letters DPG on a dark blue background.  White geometric cubes and bold text on an orange background represent 9 Industry, Innovation and Infrastructure, which is one of the United Nations Sustainable Development Goals.  A white equal sign surrounded by four arrows pointing outward on a pink background represent 9 reduced inequalities, which is one of the United Nations Sustainable Development Goals.
© 2025 TYPO3 Association

Information

  • Decision makers
  • Users
  • Developers
  • Contact form

Downloads

  • TYPO3 CMS
  • Extensions for TYPO3

Community

  • my.typo3.org
  • Slack for TYPO3 community
  • TYPO3 Code of Conduct

Popular links

  • Legal Notice
  • TYPO3.com
  • TYPO3 Association
  • Privacy Policy
  • Social Media Privacy Policy