For all of you who are not that deeply involved in the making of TYPO3 v5, I have collected the most important bits of last month's activities.
It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.
It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.
The core team is proud to announce the second Release Candidate of TYPO3 version 4.2. We now think that we do have all blockers for a final release fixed so that if no critical bugs are found in this release candidate this will...
It has been discovered that the extensions pmk_rssnewsexport and cm_rdfexport are vulnerable to SQL Injection attacks.
It has been discovered that the extension de_phpot is vulnerable to multiple SQL Injection flaws and other types of security issues.
"Sites made with TYPO3" is revamped and is now up for entering reference Websites made with TYPO3.