TYPO3 Logo
  • TYPO3 CMS
    • Features
      • Smart Content Management
      • Secure Performant Scalable
      • Universal Frontend User Experience
      • Professional Open Source
      • Open Extensible Customizable
      • Digital Marketing Enabled
      • Massively Multisite Multilingual
    • Development Roadmap
      • TYPO3 Development Roadmap
      • Maintenance Releases Schedule
    • Strategy
    • Core Development
    • Release News
      • TYPO3 11 Release Notes
      • TYPO3 10 Release Notes
      • TYPO3 9 Release Notes
      • TYPO3 8 Release Notes
      • TYPO3 7 Release Notes
    • Documentation
    • Comparison Cards
    • System Requirements
    • Download & Install
    • Getting Started
    • Fluid Template Engine
  • Community
    • Events
    • Meet the Community
      • Communicate: Where and how
      • User Groups
      • StackOverflow
      • Forum
      • Chat (Slack)
      • how to use Slack
      • Regular Open Sprints
      • You, me, and TYPO3!
    • Contribute / Get Involved
      • TYPO3 remote days
      • Become an Association Member
      • Get your My TYPO3 account
      • Donate
      • Mentorship
      • Community Writers Program
    • Teams & Committees
      • TYPO3 Development
      • Academic
      • Accessibility
      • Best Practices
      • Communication Coordination
      • Community Expansion
      • Content
      • Content Types
      • Documentation
      • Education & Certification
      • Localization
      • Marketing
      • Ombudsperson
      • Security
      • Server
      • TYPO3 CMS Product Strategy Group
      • typo3.org website
      • User Experience (UX)
    • Values and Proceedings
      • Code of Conduct
      • Community Mediation
      • Conflict of Interest Policy
      • Social Media Guidelines
      • Decision-Making Processes, Contribution and Participation
      • Open Web Manifesto
      • Policy for Committees & Official Teams
      • Usage of Titles
      • Vision, Mission, Purpose
    • Team Leader Meetings
    • Data Protection Corner
      • Training for the TYPO3 teams
    • Services
      • e-mail-addresses
  • The Project
    • News
      • RSS feed
      • Security Advisories
      • This Month in TYPO3
      • Podcast
    • Our Products
    • TYPO3 Association
      • Become a Member
      • Our Members
      • Structure
      • Association News
      • Partnerships
      • Funding & Finances
      • General Assembly
      • By-Laws & proceedings
      • Contact
      • Association Strategy
    • The Brand
      • Trademarks
      • Style Guide
      • TYPO3 slidedeck
      • Spelling TYPO3
    • History
    • Press
      • Press Releases
      • TYPO3 v9 Release Material
      • TYPO3 v10 Release Material
      • TYPO3 v11 Release Material
      • TYPO3 v12 Release Material
      • TYPO3 v13 Release Material
    • Licenses
    • Technology Supporters
  • Certification
  • Help & Support
    • Documentation
      • Getting Started
      • Video Tutorials
      • What's New
    • Security Advisories
      • TYPO3 CMS
      • TYPO3 Extensions
      • Public Service Announcements
      • Security Advisories (RSS Feed)
    • Professional Services
    • Official TYPO3 Forum
    • TYPO3 LTS Extended Support
    • Stack Overflow
  • Search
  • Login
  • Overview
  • Features +
  • Development Roadmap +
  • Strategy
  • Core Development
  • Release News +
  • Documentation
  • Comparison Cards
  • System Requirements
  • Download & Install
  • Getting Started
  • Fluid Template Engine
  • Smart Content Management
  • Secure Performant Scalable
  • Universal Frontend User Experience
  • Professional Open Source
  • Open Extensible Customizable
  • Digital Marketing Enabled
  • Massively Multisite Multilingual
  • TYPO3 Development Roadmap
  • Maintenance Releases Schedule
  • TYPO3 11 Release Notes
  • TYPO3 10 Release Notes
  • TYPO3 9 Release Notes
  • TYPO3 8 Release Notes
  • TYPO3 7 Release Notes

Professional Content Management

Free and open source, TYPO3 CMS is the most widely used enterprise-level CMS.

Test TYPO3 now:

TYPO3 live demo
  • TYPO3 Community
  • Events
  • Meet the Community +
  • Contribute / Get Involved +
  • Teams & Committees +
  • Values and Proceedings +
  • Team Leader Meetings
  • Data Protection Corner +
  • Services +
  • Communicate: Where and how
  • User Groups
  • StackOverflow
  • Forum
  • Chat (Slack)
  • how to use Slack
  • Regular Open Sprints
  • You, me, and TYPO3!
  • TYPO3 remote days
  • Become an Association Member
  • Get your My TYPO3 account
  • Donate
  • Mentorship
  • Community Writers Program
  • TYPO3 Development
  • Academic
  • Accessibility
  • Best Practices
  • Communication Coordination
  • Community Expansion
  • Content
  • Content Types
  • Documentation
  • Education & Certification
  • Localization
  • Marketing
  • Ombudsperson
  • Security
  • Server
  • TYPO3 CMS Product Strategy Group
  • typo3.org website
  • User Experience (UX)
  • Code of Conduct
  • Community Mediation
  • Conflict of Interest Policy
  • Social Media Guidelines
  • Decision-Making Processes, Contribution and Participation
  • Open Web Manifesto
  • Policy for Committees & Official Teams
  • Usage of Titles
  • Vision, Mission, Purpose
  • Training for the TYPO3 teams
  • e-mail-addresses

Inspire people to share

Offer your skills and contribute to the project. The community is growing and does more than just coding. 

  • The TYPO3 Project
  • News +
  • Our Products
  • TYPO3 Association +
  • The Brand +
  • History
  • Press +
  • Licenses
  • Technology Supporters
  • RSS feed
  • Security Advisories
  • This Month in TYPO3
  • Podcast
  • Become a Member
  • Our Members
  • Structure
  • Association News
  • Partnerships
  • Funding & Finances
  • General Assembly
  • By-Laws & proceedings
  • Contact
  • Association Strategy
  • Trademarks
  • Style Guide
  • TYPO3 slidedeck
  • Spelling TYPO3
  • Press Releases
  • TYPO3 v9 Release Material
  • TYPO3 v10 Release Material
  • TYPO3 v11 Release Material
  • TYPO3 v12 Release Material
  • TYPO3 v13 Release Material

A Community Effort

TYPO3 CMS is an Open Source project managed by the TYPO3 Association.

The Project
  • Getting Help & Support
  • Documentation +
  • Security Advisories +
  • Professional Services
  • Official TYPO3 Forum
  • TYPO3 LTS Extended Support
  • Stack Overflow
  • Getting Started
  • Video Tutorials
  • What's New
  • TYPO3 CMS
  • TYPO3 Extensions
  • Public Service Announcements
  • Security Advisories (RSS Feed)

Do you have a question?

Ask the community or a professional partner.

Sort by
  • Relevance
  • Title
  • Creation Date
  • All 5056
  • News 2465
  • Extensions 1919
  • Composer packages 347
  • Pages 306
  • Events 19
  1. SR GD Crop & Resize (srgd)

    Crop and Resize with GD. Usefull when ImageMagick is not available on the hoster. Idea from jb_gd_resize Typo3 extension and Smart Image Resizer script. Report to web@sruegg.ch

    Show extension details Download ZIP of version 2.0.2

    Last upload: 17th September 2011 by Sebastien Ruegg
  2. SQL-based Data Provider - Tesseract project (dataquery)

    Assembles a query on data stored in the TYPO3 CMS local database, automatically enforcing criteria like language, publication date, etc. More info on http://www.typo3-tesseract.com/

    This extension supports TYPO3:

    Show extension details Download ZIP of version 2.1.3 Extension documentation

    Last upload: 4th June 2019 by Francois Suter (Cobweb)
  3. SQL injection in macina_banners / ric_rotation

    Component Type: Third party extensions. These extensions are not part of the TYPO3 default installation Affected Versions: Affected is macina_banners (version 1.4.0 and below) and its descendant…

    Published: 8th June 2007
  4. SQL Injection vulnerability in extension wt_directory (wt_directory)

    Release Date: June 15, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.4.1 and below Vulnerability Type: SQL…

    Published: 15th June 2015 by Nicole Cordes
  5. SQL Injection vulnerability in extension Store Locator (locator)

    Release Date: June 15, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 3.3.0 and below Vulnerability Type: SQL…

    Published: 15th June 2015 by Franz G. Jahn
  6. SQL Injection vulnerability in extension Smoelenboek (ncgov_smoelenboek)

    Release Date: June 15, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.0.8 and below Vulnerability Type: SQL…

    Published: 15th June 2015 by Nicole Cordes
  7. SQL Injection vulnerability in extension RealURL: speaking paths for TYPO3 (realurl)

    Release Date: September 25, 2013 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 1.12.6 and below Vulnerability Type:…

    Published: 25th September 2013 by Franz G. Jahn
  8. SQL Injection vulnerability in extension Multishop (multishop)

    Release Date: June 03, 2013 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 2.0.38 and below Vulnerability Type: SQL…

    Published: 3rd June 2013 by Franz G. Jahn
  9. SQL Injection vulnerability in extension Formhandler (formhandler)

    Release Date: September 25, 2013 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Version: 1.6.1 and alll versions below Vulnerability…

    Published: 25th September 2013 by Franz G. Jahn
  10. SQL Injection vulnerability in extension Faceted Search (ke_search)

    Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 0.3.0 and all versions below Vulnerability Type: SQL Injection…

    Published: 29th June 2011 by Helmut Hummel
  11. SQL Injection vulnerability in extension FAQ - Frequently Asked Questions (js_faq)

    Release Date: June 15, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.2.0 and below Vulnerability Type: SQL…

    Published: 15th June 2015 by Nicole Cordes
  12. SQL Injection vulnerability in extension Developer Log (devlog)

    Release Date: June 15, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 2.11.3 and below Vulnerability Type: SQL…

    Published: 15th June 2015 by Nicole Cordes
  13. SQL Injection vulnerability in extension CoolURI (cooluri)

    Release Date: February 19, 2012 Bulletin Update: November 06, 2014 (added CVE) Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions:…

    Published: 19th February 2013 by Franz G. Jahn
  14. SQL Injection vulnerability in extension Basic SEO Features (seo_basics)

    Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 0.8.2 and below Vulnerability Type: SQL Injection Severity: High…

    Published: 7th June 2012 by Markus Bucher
  15. SQL Injection vulnerabilities in extension "WEC Discussion Forum" (wec_discussion)

    Release Date: April 7, 2011 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: Version 2.1.0 and all versions below Vulnerability…

    Published: 7th April 2011 by Marcus Krause
  16. SQL Injection in system extension indexed_search

    Component Type: System extension, part of the TYPO3 default installation. Affected Versions: TYPO3 versions 3.x, 4.0 to 4.0.7, 4.1 to 4.1.3. Vulnerability Type: SQL Injection. Severity: Low. Problem…

    Published: 10th December 2007
  17. SQL Injection in low-level Query Generator

    Component Type: TYPO3 CMS Subcomponent: Query Generator (ext:lowlevel) Release Date: December 17, 2019 Vulnerability Type: SQL Injection Affected Versions: 8.0.0-8.7.29 and 9.0.0-9.5.11 and…

    Published: 17th December 2019 by Oliver Hader
  18. SQL Injection in fechangepassword

    Component Type: Third party extension. This extension is not part of the TYPO3 default installation Affected Versions: Version 2.1.2 and all versions below Vulnerability Type: SQL Injection Severity:…

    Published: 10th July 2007
  19. SQL Injection in extension Commerce (commerce)

    Component Type: Third party extension. This extension is not part of the TYPO3 default installation. Affected Versions: Version 0.9.6 and below. Vulnerability Type: SQL Injection Severity: HIGH…

    Published: 20th October 2008
  20. SQL Injection in extension "phpmyadmin" (phpmyadmin)

    Release Date: March 10, 2020 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Vulnerability Type: SQL Injection Affected Versions: 5.4.0 and below…

    Published: 10th March 2020 by Torben Hansen
  21. SQL Injection in extension "phpMyAdmin" (phpmyadmin)

    Release Date: May 12, 2020 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: phpMyAdmin (ext:phpmyadmin) Vulnerability Type: SQL…

    Published: 12th May 2020 by Torben Hansen
  22. SQL Injection in extension "ipandlanguageredirect" (ipandlanguageredirect)

    Release Date: June 13, 2023 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "ipandlanguageredirect" (ipandlanguageredirect) Composer…

    Published: 13th June 2023 by Torben Hansen
  23. SQL Injection in extension "http:BL Blocking" (mh_httpbl)

    Release Date: September 30, 2015 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Affected Versions: version 1.1.7 and below Vulnerability Type:…

    Published: 30th September 2015 by Nicole Cordes
  24. SQL Injection in extension "comsolit Suggest" (comsolit_suggest)

    Release Date: May 07, 2019 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Vulnerability Type: SQL Injection Affected Versions: 2.0.1 and below…

    Published: 7th May 2019 by Torben Hansen
  25. SQL Injection in extension "VHS: Fluid ViewHelpers" (vhs)

    Release Date: March 16, 2021 Component Type: Third party extension. This extension is not a part of the TYPO3 default installation. Component: "VHS: Fluid ViewHelpers" (vhs) Vulnerability Type: SQL…

    Published: 16th March 2021 by Torben Hansen
    • «
    • ‹
    • ....
    • 94
    • 95
    • 96
    • 97
    • 98
    • 99
    • 100
    • 101
    • 102
    • 103
    • ....
    • ›
    • »
Ready to get started?
Download TYPO3 CMS for free!
Download Get more info
TYPO3
🦋
Logo with a blue badge and white checkmark next to the letters DPG on a dark blue background.  White geometric cubes and bold text on an orange background represent 9 Industry, Innovation and Infrastructure, which is one of the United Nations Sustainable Development Goals.  A white equal sign surrounded by four arrows pointing outward on a pink background represent 9 reduced inequalities, which is one of the United Nations Sustainable Development Goals.
© 2025 TYPO3 Association

Information

  • Decision makers
  • Users
  • Developers
  • Contact form

Downloads

  • TYPO3 CMS
  • Extensions for TYPO3

Community

  • my.typo3.org
  • Slack for TYPO3 community
  • TYPO3 Code of Conduct

Popular links

  • Legal Notice
  • TYPO3.com
  • TYPO3 Association
  • Privacy Policy
  • Social Media Privacy Policy