[TYPO3-announce] [Ticket#2026051910000022] Vulnerabilities in multiple third party TYPO3 CMS extensions
TYPO3 Security Team
security at typo3.org
Tue May 19 11:37:43 CEST 2026
Dear TYPO3 users,
several vulnerabilities have been found in the following third party TYPO3
extensions:
"Site Crawler" (crawler)"Frontend User Registration" (sf_register)"News
system" (news)"Faceted Search" (ke_search)"Address List" (tt_address)"Content
Element Selector" (ceselector)
For further information on the issues, please read the related advisories
TYPO3-EXT-SA-2026-008, TYPO3-EXT-SA-2026-009, TYPO3-EXT-SA-2026-010,
TYPO3-EXT-SA-2026-011, TYPO3-EXT-SA-2026-012 and TYPO3-EXT-SA-2026-013
which were published today:
TYPO3-EXT-SA-2026-008: Remote Code Execution in extension "Site Crawler"
(crawler)
[1]https://typo3.org/security/advisory/typo3-ext-sa-2026-008
TYPO3-EXT-SA-2026-009: Broken Access Control in extension "Frontend User
Registration" (sf_register)
[2]https://typo3.org/security/advisory/typo3-ext-sa-2026-009
TYPO3-EXT-SA-2026-010: SQL Injection in extension "News system" (news)
[3]https://typo3.org/security/advisory/typo3-ext-sa-2026-010
TYPO3-EXT-SA-2026-011: Multiple vulnerabilities in extension "Faceted Search"
(ke_search)
[4]https://typo3.org/security/advisory/typo3-ext-sa-2026-011
TYPO3-EXT-SA-2026-012: SQL Injection in extension "Address List" (tt_address)
[5]https://typo3.org/security/advisory/typo3-ext-sa-2026-012
TYPO3-EXT-SA-2026-013: Remote Code Execution in extension "Content Element
Selector" (ceselector)
[6]https://typo3.org/security/advisory/typo3-ext-sa-2026-013
In general the TYPO3 Security Team recommends to read the following pages:
The TYPO3 Security Guide:
[7]https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html
Make sure you are subscribed to the TYPO3 Announce List:
[8]https://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce
See all TYPO3 security advisories:
[9]https://typo3.org/help/security-advisories
Best regards,
Torben Hansen
Member of the TYPO3 Security Team
--
TYPO3 Security Team homepage:
[10]https://typo3.community/contribute/teams-committees/security
E-Mail: security at typo3.org
Please note: When replying to this e-mail, please leave the header intact.
[1] https://typo3.org/security/advisory/typo3-ext-sa-2026-008
[2] https://typo3.org/security/advisory/typo3-ext-sa-2026-009
[3] https://typo3.org/security/advisory/typo3-ext-sa-2026-010
[4] https://typo3.org/security/advisory/typo3-ext-sa-2026-011
[5] https://typo3.org/security/advisory/typo3-ext-sa-2026-012
[6] https://typo3.org/security/advisory/typo3-ext-sa-2026-013
[7] https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html
[8] https://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce
[9] https://typo3.org/help/security-advisories
[10] https://typo3.community/contribute/teams-committees/security
-------------- next part --------------
A non-text attachment was scrubbed...
Name: pgp_sign.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.typo3.org/pipermail/typo3-announce/attachments/20260519/401cad95/attachment.pgp>
More information about the TYPO3-announce
mailing list