TYPO3 Logo
  • TYPO3 CMS
    • Features
      • Smart Content Management
      • Secure Performant Scalable
      • Universal Frontend User Experience
      • Professional Open Source
      • Open Extensible Customizable
      • Digital Marketing Enabled
      • Massively Multisite Multilingual
    • Development Roadmap
      • TYPO3 Development Roadmap
      • Maintenance Releases Schedule
    • Strategy
    • Core Development
    • Release News
      • TYPO3 11 Release Notes
      • TYPO3 10 Release Notes
      • TYPO3 9 Release Notes
      • TYPO3 8 Release Notes
      • TYPO3 7 Release Notes
    • Documentation
    • Comparison Cards
    • System Requirements
    • Download & Install
    • Getting Started
    • Fluid Template Engine
  • Community
    • Events
    • Meet the Community
      • Communicate: Where and how
      • User Groups
      • StackOverflow
      • Forum
      • Chat (Slack)
      • how to use Slack
      • Regular Open Sprints
      • You, me, and TYPO3!
    • Contribute / Get Involved
      • TYPO3 remote days
      • Become an Association Member
      • Get your My TYPO3 account
      • Donate
      • Mentorship
      • Community Writers Program
    • Teams & Committees
      • TYPO3 Development
      • Academic
      • Accessibility
      • Best Practices
      • Communication Coordination
      • Community Expansion
      • Content
      • Content Types
      • Documentation
      • Education & Certification
      • Localization
      • Marketing
      • Ombudsperson
      • Security
      • Server
      • TYPO3 CMS Product Strategy Group
      • typo3.org website
      • User Experience (UX)
    • Values and Proceedings
      • Code of Conduct
      • Community Mediation
      • Conflict of Interest Policy
      • Social Media Guidelines
      • Decision-Making Processes, Contribution and Participation
      • Open Web Manifesto
      • Policy for Committees & Official Teams
      • Usage of Titles
      • Vision, Mission, Purpose
    • Team Leader Meetings
    • Data Protection Corner
      • Training for the TYPO3 teams
    • Services
      • e-mail-addresses
  • The Project
    • News
      • RSS feed
      • Security Advisories
      • This Month in TYPO3
      • Podcast
    • Our Products
    • TYPO3 Association
      • Become a Member
      • Our Members
      • Structure
      • Association News
      • Partnerships
      • Funding & Finances
      • General Assembly
      • By-Laws & proceedings
      • Contact
      • Association Strategy
    • The Brand
      • Trademarks
      • Style Guide
      • TYPO3 slidedeck
      • Spelling TYPO3
    • History
    • Press
      • Press Releases
      • TYPO3 v9 Release Material
      • TYPO3 v10 Release Material
      • TYPO3 v11 Release Material
      • TYPO3 v12 Release Material
      • TYPO3 v13 Release Material
    • Licenses
    • Technology Supporters
  • Certification
  • Help & Support
    • Documentation
      • Getting Started
      • Video Tutorials
      • What's New
    • Security Advisories
      • TYPO3 CMS
      • TYPO3 Extensions
      • Public Service Announcements
      • Security Advisories (RSS Feed)
    • Professional Services
    • Official TYPO3 Forum
    • TYPO3 LTS Extended Support
    • Stack Overflow
  • Search
  • Login
  • Overview
  • Features +
  • Development Roadmap +
  • Strategy
  • Core Development
  • Release News +
  • Documentation
  • Comparison Cards
  • System Requirements
  • Download & Install
  • Getting Started
  • Fluid Template Engine
  • Smart Content Management
  • Secure Performant Scalable
  • Universal Frontend User Experience
  • Professional Open Source
  • Open Extensible Customizable
  • Digital Marketing Enabled
  • Massively Multisite Multilingual
  • TYPO3 Development Roadmap
  • Maintenance Releases Schedule
  • TYPO3 11 Release Notes
  • TYPO3 10 Release Notes
  • TYPO3 9 Release Notes
  • TYPO3 8 Release Notes
  • TYPO3 7 Release Notes

Professional Content Management

Free and open source, TYPO3 CMS is the most widely used enterprise-level CMS.

Test TYPO3 now:

TYPO3 live demo
  • TYPO3 Community
  • Events
  • Meet the Community +
  • Contribute / Get Involved +
  • Teams & Committees +
  • Values and Proceedings +
  • Team Leader Meetings
  • Data Protection Corner +
  • Services +
  • Communicate: Where and how
  • User Groups
  • StackOverflow
  • Forum
  • Chat (Slack)
  • how to use Slack
  • Regular Open Sprints
  • You, me, and TYPO3!
  • TYPO3 remote days
  • Become an Association Member
  • Get your My TYPO3 account
  • Donate
  • Mentorship
  • Community Writers Program
  • TYPO3 Development
  • Academic
  • Accessibility
  • Best Practices
  • Communication Coordination
  • Community Expansion
  • Content
  • Content Types
  • Documentation
  • Education & Certification
  • Localization
  • Marketing
  • Ombudsperson
  • Security
  • Server
  • TYPO3 CMS Product Strategy Group
  • typo3.org website
  • User Experience (UX)
  • Code of Conduct
  • Community Mediation
  • Conflict of Interest Policy
  • Social Media Guidelines
  • Decision-Making Processes, Contribution and Participation
  • Open Web Manifesto
  • Policy for Committees & Official Teams
  • Usage of Titles
  • Vision, Mission, Purpose
  • Training for the TYPO3 teams
  • e-mail-addresses

Inspire people to share

Offer your skills and contribute to the project. The community is growing and does more than just coding. 

  • The TYPO3 Project
  • News +
  • Our Products
  • TYPO3 Association +
  • The Brand +
  • History
  • Press +
  • Licenses
  • Technology Supporters
  • RSS feed
  • Security Advisories
  • This Month in TYPO3
  • Podcast
  • Become a Member
  • Our Members
  • Structure
  • Association News
  • Partnerships
  • Funding & Finances
  • General Assembly
  • By-Laws & proceedings
  • Contact
  • Association Strategy
  • Trademarks
  • Style Guide
  • TYPO3 slidedeck
  • Spelling TYPO3
  • Press Releases
  • TYPO3 v9 Release Material
  • TYPO3 v10 Release Material
  • TYPO3 v11 Release Material
  • TYPO3 v12 Release Material
  • TYPO3 v13 Release Material

A Community Effort

TYPO3 CMS is an Open Source project managed by the TYPO3 Association.

The Project
  • Getting Help & Support
  • Documentation +
  • Security Advisories +
  • Professional Services
  • Official TYPO3 Forum
  • TYPO3 LTS Extended Support
  • Stack Overflow
  • Getting Started
  • Video Tutorials
  • What's New
  • TYPO3 CMS
  • TYPO3 Extensions
  • Public Service Announcements
  • Security Advisories (RSS Feed)

Do you have a question?

Ask the community or a professional partner.

Sort by
  • Relevance
  • Title
  • Creation Date
  • All 5045
  • News 2457
  • Extensions 1918
  • Composer packages 345
  • Pages 306
  • Events 19
  1. Multiple vulnerabilities in "Aimeos shop and e-commerce framework" (aimeos)

    Release Date: June 18, 2024 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Aimeos shop and e-commerce framework" (aimeos) Composer…

    Published: 18th June 2024 by Torben Hansen
  2. Multiple vulnerabilities in "Events 2" (events2)

    Release Date: June 18, 2024 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Events 2" (events2) Composer Package Name:…

    Published: 18th June 2024 by Torben Hansen
  3. Multiple vulnerabilities in BibTex Publications (si_bibtex)

    Release Date: December 15, 2014 Bulletin Update: January 9, 2015 (added CVEs) Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions:…

    Published: 15th December 2014 by Marcus Krause
  4. Multiple vulnerabilities in Content Rating (content_rating)

    Release Date: January 9, 2015 Bulletin Update: February 23, 2015 (added CVEs) Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions:…

    Published: 9th January 2015 by Marcus Krause
  5. Multiple vulnerabilities in Content Rating Extbase (content_rating_extbase)

    Release Date: January 9, 2015 Bulletin Update: February 23, 2015 (added CVEs) Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions:…

    Published: 9th January 2015 by Marcus Krause
  6. Multiple vulnerabilities in Drag Drop Mass Upload (ameos_dragndropupload)

    Release Date: December 15, 2014 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: 3.1.1 and all versions below Vulnerability…

    Published: 15th December 2014 by Marcus Krause
  7. Multiple vulnerabilities in Extension "Dated News" (dated_news)

    Release Date: August 10, 2021 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Dated News" (dated_news) Vulnerability Type: SQL…

    Published: 10th August 2021 by Torben Hansen
  8. Multiple vulnerabilities in Extension "Miniorange Saml" (miniorange_saml)

    Release Date: August 10, 2021 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Miniorange Saml" (miniorange_saml) Vulnerability Type:…

    Published: 10th August 2021 by Torben Hansen
  9. Multiple vulnerabilities in TYPO3 Core

    Component Type: TYPO3 Core Affected Versions: TYPO3 versions 4.0.0 to 4.0.9, 4.1.0 to 4.1.7, 4.2.0 to 4.2.3 Vulnerability Types: Broken Authentication and Session Management, Cross-Site Scripting,…

    Published: 20th January 2009 by Marcus Krause
  10. Multiple vulnerabilities in TYPO3 Core

    Component Type: TYPO3 Core Affected Versions: TYPO3 versions 4.0.13 and below, 4.1.12 and below, 4.2.9 and below, 4.3.0beta1 and below Vulnerability Types: SQL injection, Cross-site scripting (XSS),…

    Published: 22nd October 2009 by Helmut Hummel
  11. Multiple vulnerabilities in TYPO3 Core

    Component Type: TYPO3 Core Affected Versions: 4.2.15 and below, 4.3.8 and below, 4.4.4 and below Vulnerability Types: Arbitrary Code Execution, Path Traversal, Cross-Site Scripting (XSS), SQL…

    Published: 16th December 2010 by Helmut Hummel
  12. Multiple vulnerabilities in TYPO3 third party extensions

    Release Date: March 05, 2009 Please read first: This Collective Security Bulletin (CSB) is a listing of vulnerable extensions with neither significant download numbers, nor other special importance…

    Published: 5th March 2009 by Marcus Krause
  13. Multiple vulnerabilities in civserv

    Component Type: Third party extension. This extension is not part of the TYPO3 default installation Affected Versions: Version 4.2.4 and all versions below Vulnerability Type: XSS and SQL Injection…

    Published: 12th July 2007
  14. Multiple vulnerabilities in extension "Adminer" (t3adminer)

    Release Date: April 26, 2022 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Adminer" (t3adminer) Vulnerability Type: Server-side…

    Published: 26th April 2022 by Torben Hansen
  15. Multiple vulnerabilities in extension "Ajax mail subscription" (ods_ajaxmailsubscription)

    Release Date: March 24, 2016 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.4.4 and below Vulnerability Type:…

    Published: 24th March 2016 by Nicole Cordes
  16. Multiple vulnerabilities in extension "Backup Plus" (ns_backup)

    Release Date: May 20, 2025 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Backup Plus" (ns_backup) Composer Package Name:…

    Published: 20th May 2025 by Elias Häußler
  17. Multiple vulnerabilities in extension "Canto Extension" (canto_extension)

    Release Date: June 13, 2023 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Canto Extension" (canto_extension) Composer Package Name:…

    Published: 13th June 2023 by Torben Hansen
  18. Multiple vulnerabilities in extension "DRC News Comment" (news_comment)

    Release Date: December 18, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.0.7 and below Vulnerability Type:…

    Published: 19th December 2017 by Nicole Cordes
  19. Multiple vulnerabilities in extension "Direct Mail" (direct_mail)

    Release Date: May 12, 2020 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: Direct Mail (ext:direct_mail) Vulnerability Type: Denial of…

    Published: 12th May 2020 by Torben Hansen
  20. Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)

    Release Date: September 02, 2020 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: Event management and registration (sf_event_mgt)…

    Published: 2nd September 2020 by Torben Hansen
  21. Multiple vulnerabilities in extension "Fe user statistic" (festat)

    Release Date: March 03, 2016 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 0.3.2 and below Vulnerability Type:…

    Published: 3rd March 2016 by Nicole Cordes
  22. Multiple vulnerabilities in extension "File manager" (ameos_filemanager)

    Release Date: November 07, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.0.1 and below Vulnerability Type:…

    Published: 7th November 2017 by Torben Hansen
  23. Multiple vulnerabilities in extension "Front End User Registration" (sr_feuser_register)

    Release Date: May 20, 2025 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "Front End User Registration" (sr_feuser_register) Composer…

    Published: 20th May 2025 by Elias Häußler
  24. Multiple vulnerabilities in extension "JobControl" (dmmjobcontrol)

    Release Date: December 18, 2017 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.16.0 and below Vulnerability Type:…

    Published: 19th December 2017 by Stephan Großberndt
  25. Multiple vulnerabilities in extension "MKSamlAuth" (mksamlauth)

    Release Date: December 17, 2019 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Vulnerability Type: Broken Authentication, Authentication Bypass…

    Published: 17th December 2019 by Torben Hansen
    • «
    • ‹
    • ....
    • 76
    • 77
    • 78
    • 79
    • 80
    • 81
    • 82
    • 83
    • 84
    • 85
    • ....
    • ›
    • »
Ready to get started?
Download TYPO3 CMS for free!
Download Get more info
TYPO3
🦋
Logo with a blue badge and white checkmark next to the letters DPG on a dark blue background.  White geometric cubes and bold text on an orange background represent 9 Industry, Innovation and Infrastructure, which is one of the United Nations Sustainable Development Goals.  A white equal sign surrounded by four arrows pointing outward on a pink background represent 9 reduced inequalities, which is one of the United Nations Sustainable Development Goals.
© 2025 TYPO3 Association

Information

  • Decision makers
  • Users
  • Developers
  • Contact form

Downloads

  • TYPO3 CMS
  • Extensions for TYPO3

Community

  • my.typo3.org
  • Slack for TYPO3 community
  • TYPO3 Code of Conduct

Popular links

  • Legal Notice
  • TYPO3.com
  • TYPO3 Association
  • Privacy Policy
  • Social Media Privacy Policy