May 2026 in TYPO3 Six vulnerabilities, two releases and new foundations for the ecosystem

A monthly round-up of the most important developments in the world of TYPO3: security advisories affecting almost every installation, maintenance releases, news from the TYPO3 Association and the community — with a practical perspective for administrators and website owners

Blog 11.06.2026

In a nutshell

Most urgent:
On 19 May, six security advisories were published for extensions in a single week — including RCE in ceselector and crawler, and SQL injection in tt_address and news. The latter two are among the most popular TYPO3 extensions — if you are using them, update immediately.
Maintenance releases:
Two release cycles in a single month: 14.3.1 and 13.4.29 (12 May) and 14.3.2 and 13.4.30 (26 May). Both LTS branches are actively maintained.
Association:
New Compliance Officer (Rachel Foucard), a complete SEAL ecosystem with AI vector search, and certification sprints aimed at launching the v14 exams at Developer Days in August.
Community:
Fluid in VSCode — the first official extension under FriendsOfTYPO3. Updated sitepackage tutorial for v14. Changes to the Bug Bounty rules from 31 May.
What to do now:
Check whether your installation uses any of the six affected extensions, update the Core to 14.3.2 / 13.4.30 and schedule a security review — particularly if you are subject to NIS2.

May 2026 was a month of foundations within the TYPO3 CMS ecosystem — foundations that were built, documented and defended. On the one hand, there was calm, methodical work: two maintenance releases, certification sprints and new tools for developers. On the other hand, it was a week in which the Security Team published six advisories for extensions at once, including two critical ones. Below is a summary of what really matters — from a practical perspective: what this means for your installation and what you should do first

Security: six advisories in a single week

On 19 May, the TYPO3 Security Team published a series of six advisories concerning third-party extensions. This is an unusual cluster of advisories — and not a coincidence: the Bug Bounty programme for vulnerabilities in extensions ends on 31 May, so researchers were reporting their findings ahead of the deadline. For administrators, this means one thing: check your list of extensions today.

  • ceselector (Content Element Selector) RCE — CRITICAL

    TYPO3-EXT-SA-2026-013 Remote
    Code Execution — the most serious vulnerability category. An attacker can execute arbitrary code on the server. If you are using this extension, updating is absolutely urgent — there is no scenario in which you can afford to delay it.

  • RCE crawler — CRITICAL

    TYPO3-EXT-SA-2026-008
    : The second RCE in this series. The crawler extension is widely used in larger installations (cache generation, indexing). High priority for updating

  • tt_address SQL Injection

    TYPO3-EXT-SA-2026-012tt_address
    is one of the most commonly installed TYPO3 extensions — for contact lists, staff lists, branch lists and directions maps. If your website displays any address details, it is almost certainly using this extension. An SQL injection attack allows an attacker to read or modify data in the database.

  • news: SQL Injection

    TYPO3-EXT-SA-2026-010 The ‘news’ extension
    is an absolute standard — news items, announcements, blog posts. It is used in the vast majority of TYPO3 installations in Poland, from local authorities to corporations. Urgent update required.

  • ke_search XXE, Path Traversal, Information Disclosure

    TYPO3-EXT-SA-2026-011
    Three vulnerabilities in the popular ke_search search engine. These allow files to be read from the server and system information to be disclosed. If you are using ke_search instead of Indexed Search or Solr, please update. 

  • sf_register – Broken Access Control

    TYPO3-EXT-SA-2026-009
    : An access control vulnerability in the frontend user registration extension. This may allow access to functions or data without the appropriate permissions. Relevant for websites with user accounts, membership portals and NGOs.

Why is this important for Polish installations?

tt_address and news are extensions found in almost every TYPO3 installation — including those in the public sector. A local authority website with a list of departments and news items? tt_address + news. A hospital portal with a list of clinics and announcements?
The same applies. An NGO’s website with a team page and blog posts? The same applies. The combination of an SQL injection with personal data in the database (forms, accounts) creates a risk of a data breach within the meaning of the GDPR — with all the associated reporting obligations (72 hours to report to the UODO).
For entities covered by the amendment to the KSC Act (NIS2) — hospitals, local authorities, universities — a security patch that has not been applied is precisely the kind of negligence that an auditor will highlight in a report. Vulnerability management is one of the mandatory measures — and a publicly disclosed vulnerability for which a patch is available has a clear remediation path and a clear deadline.

Maintenance releases: two cycles in a single month

May saw the release of two sets of stable releases for both supported LTS branches:

• 12 May — TYPO3 14.3.1 and 13.4.
29• 26 May — TYPO3 14.3.2 and 13.4.

30Two patch cycles in a single month signal active, attentive maintenance of both branches — both the new v14 LTS (released on 21 April) and the still widely used v13. If your installation is not on 14.3.2 or 13.4.30 — plan to update during the next maintenance window. We’d also like to remind you of the wider context: community support for v12 ends on 31 October 2026 — there are five months left. Details can be found in our article on migrating to TYPO3 v14 LTS.

TYPO3 Association: new structures and tools

Compliance Officer a new role within the Association’s structure

The TYPO3 Association has created a new role of Compliance Officer, which has been taken up by Rachel Foucard. This role is situated outside the Board — deliberately so as to ensure its independence. Responsibilities include overseeing ethical compliance, managing conflicts of interest, mediating disputes and preparing the organisation for the requirements of the Cyber Resilience Act. For TYPO3 business users, this is a positive sign: the ecosystem is professionalising its governance at precisely the moment when European regulations (CRA, NIS2) are beginning to require software providers to demonstrate documented accountability.

The SEAL ecosystem is complete AI-powered search

Tim Lochmüller has completed a project funded by the Community Budget Q1/2026: the SEAL ecosystem. It comprises three components: Index 2.2.0 (content indexing), SEAL 1.1.0 (faceted search, geofencing, analytics dashboard) and SEAL AI 1.0.0 — vector search with AI-generated result summaries. This is the third major search option in TYPO3 alongside Indexed Search and Apache Solr — particularly interesting for projects seeking a modern semantic search solution without having to maintain a separate Solr infrastructure.

Certification August course and v14 exams

The Education Committee held a sprint in Lübeck — four certification task forces are working on restructuring the skill trees and are using AI-assisted review to verify exam questions. Meanwhile, the TCCI Task Force met on 9–10 May in Filderstadt: six people worked through around 130 skills. 
An interesting development: in the new TCCI exam, the role of TypoScript is diminishing in favour of Fluid and data processors — this reflects the real-world evolution of how websites are built in TYPO3. The aim is to launch the v14 exams at Developer Days in Karlsruhe (6–8 August 2026). If you’re planning to take the certification, it’s worth either waiting for v14 or passing the current exam before the change, depending on your strategy.

Bug Bounty Change to the scope from 31 May

The Bug Bounty Programme is narrowing its scope: financial rewards for reporting vulnerabilities in extensions will end on 31 May 2026. Reports will continue to be accepted and coordinated by the Security Team (advisories will be published as before), but paid bounties will now cover only Core, infrastructure and servers. It is likely that this deadline explains the cluster of six advisories in May — researchers were finalising their reports before the programme ended. 

Community and developer tools

Fluid in VSCode Official support from the publisher

Simon Praetorius has released Fluid in VSCode — the first first-party extension for the editor under the FriendsOfTYPO3 banner. Features: Fluid syntax highlighting, ViewHelper snippets and live parsing performed by the actual Fluid engine (not heuristics). It also works in VSCodium, Cursor and Windsurf. For development teams, this marks the end of an era in which Fluid templates were treated as ‘plain HTML with magic tags’ — the editor finally understands what you’re writing.

Sitepackage tutorial updated for v14

Karsten Nowak from the Documentation Team has updated the official sitepackage tutorial for TYPO3 v14. This is essential reading for anyone building their own templates — whether you’re implementing your first project on v14 or training a new developer, start with the updated version.

A new wave of contributors

Kendall Litton’s article “The next wave of TYPO3” describes the younger generation of contributors joining the project — including through events such as Surf Camp in Fuerteventura. The call for papers for Developer Days is now open. April activity baseline: 71 contributors, 47 patch authors, 214 reviews — a healthy, stable rhythm for an open-source project with a 28-year history.

Events: June and beyond

The TYPO3 events calendar for the coming months is packed.

Highlights:

5–7 JuneTYPO3 Camp Vienna. We were there — a great opportunity to discuss collaboration and subcontracting with agencies from the DACH region. A report will be available soon on our blog.
22–26 JuneUN Open Source Week, New York TYPO3 as a Digital Public Good on the international
stage• 6–8 August Developer Days, Karlsruhe — Launch of the v14 certification
exams• 11–13 SeptemberTYPO3 Camp Munich
15–16 SeptemberUniversity Days, Erfurt — TYPO3 in higher
education• 23–24 SeptemberDMEXCO, Cologne
15–17 OctoberTYPO3 Camp Berlin

Teams implementing v14 may also wish to take a look at the official release materials hub: typo3.com/typo3-cms/release-materials/v14 — slides, fact sheets and screenshots that are useful when communicating with clients and management.

Checklist What to do with all this in June

✓ Check the list of extensions in your installation against the six advisories: ceselector, crawler, tt_address, news, ke_search, sf_register — and update any affected
ones✓ Update Core to 14.3.2 or 13.4.30 during the next maintenance
window✓ If you are on v12 — start planning your migration; support ends on 31 October
2026✓ If you are subject to NIS2 — document the patches applied (vulnerability management audit trail)
✓ For developers: install Fluid in VSCode and check out the updated sitepackage tutorial✓
Consider an additional layer of application protection — e.g. the TYPO3 Firewall extension, which we covered in a separate article

Frequently Asked Questions

In the TYPO3 backend: the Admin Tools → Extensions module displays a list of installed extensions along with their versions. In Composer installations: run `composer show` filtered by extension name. If you don’t have technical access, ask your agency or get in touch with us, and we’ll look into it.

Security updates (patch levels) generally do not alter functionality — the risk is minimal and the benefit is obvious. Nevertheless, it is standard practice to test them in a staging environment before deployment to production. If an extension requires a major version jump (e.g. an old version of ‘news’ that is no longer supported), then an analysis of the changes is required — this is a different scenario from a standard patch.

This is precisely the situation in which a lack of technical support for a website becomes a real risk. A publicly disclosed vulnerability is a race against time — attackers’ scanners begin searching for unpatched installations within days of the advisory being published. We offer both one-off security audits and ongoing maintenance contracts with a guaranteed response time to security advisories.

No — all six advisories issued in May relate to third-party extensions, not the Core itself. The Core received two standard maintenance releases in May (stability releases, without critical patches). This is, in fact, a typical scenario: the vast majority of vulnerabilities in the TYPO3 ecosystem relate to extensions — which is why managing them (minimising their number, ensuring regular updates, and selecting mature projects) is a key element of security.

v11 is no longer supported by the community — security patches are available exclusively via the paid ELTS. If an extension containing a vulnerability is running on v11, its new version may no longer support that TYPO3 branch — in which case, migration is the only viable option. The older the installation, the greater the risk that future security advisories will leave it unpatched.

How can we help?

If, after reading this summary, you’re unsure whether your TYPO3 installation is secure — now is a good time to carry out a review.

We offer:
✓ A quick security review — verification of the Core version and extensions against current advisories, with a report within 24–48 hours✓
Updates to affected extensions and the Core, with testing on a staging environment✓
A standing maintenance contract with a guaranteed response to every TYPO3 Security Team advisory✓
Vulnerability management documentation for NIS2 audits — for hospitals, local authorities and other entities covered by the KSC

Act. Telephone: 12 333 44 01. Email: [email protected].

About the author
Krzysztof Napora
Krzysztof Napora
Krzysztof Napora