Skip to main navigation Skip to main content Skip to page footer

Security Team

Security is taken very seriously by the developers of TYPO3. The visible part of that concern is the TYPO3 Security Team.

Report a vulnerability  Security related information can be sent to security@typo3.org.

We are responsible for all security related concerns in the TYPO3 ecosystem. This includes:

  • Handling of reported security issues for the TYPO3 core and extensions. 
  • Coordinating security fixes with the TYPO3 core team and extension developers
  • Publishing security bulletins for TYPO3 core and extension issues
  • Providing assistance for extension developers in resolving security issues
  • Providing TYPO3 security guidelines
  • Help the TYPO3 server team keeping the typo3.org infrastructure secure

How to report a Security Issue

If you have found a security issue in a TYPO3 extension or the TYPO3 core system, please report it to us by following the instructions described on this page.

How to stay informed about security updates

TYPO3 core security updates, extension security updates or unmaintained insecure extensions are announced in the form of TYPO3 Security Bulletins. We notify the TYPO3 community about the release of new bulletins via the following channels:

  • Email: To get the bulletin notification delivered to your inbox, we strongly recommend to subscribe to the typo3-announce mailing list.
  • RSS Feed: You can subscribe to the security news feed at typo3.org. 
  • X (formerly Twitter) and Mastodon: We also publish links to our Security Bulletins on X (formerly Twitter) as @typo3_security and on Mastodon as @typo3_security.

Join the TYPO3 Security Team

If you are interested in making the TYPO3 more secure and want to contribute, please contact us.

Security in TYPO3

We decided to follow a policy of least disclosure. That is the reason why we ask everyone to get in touch with the TYPO3 Security Team first whenever a security issue has been found.

Contacted by the Security Team

When you have been contacted by the TYPO3 security team and been directed to this page, please make sure to read the full page!

Extension Security Policy

This is the official policy on the handling of security incidents, as defined by the TYPO3 Security Team.

Resources

Bug Bounty Program

Since the TYPO3 project wants to encourage security reporters to analyze our products we introduced a dedicated bug bounty program.

Contact Us

If you learn about a potential security issue in the TYPO3 core or in an extension, please always contact the TYPO3 Security Team.