On 11 August 2026, the TYPO3 team released version 13.4.34. In addition to bug fixes, the release contains a security-relevant change. Version 14.3.6 was provided for TYPO3 14 at the same time. Release notes for TYPO3 13.4.34
What was fixed?
The vulnerability concerns the protection of requests to the backend and the Install Tool, an administration area for technical configuration.
Under certain conditions, attackers could trigger actions with the rights of a logged-in user. To do this, they had to be able to execute JavaScript on a domain of the affected TYPO3 installation, for example via an additional cross-site scripting vulnerability. An ordinary visit to the website alone was not sufficient for this.
TYPO3 rates the vulnerability as high. Versions 13.0.0 to 13.4.33 and 14.0.0 to 14.3.5 are affected. It was fixed with 13.4.34 and 14.3.6 respectively. Official security advisory
What we recommend
We recommend updating affected installations promptly. The conditions mentioned limit the attack options, but do not make the security update unnecessary.
Before the update, a current backup should be created and the changes checked in a separate test environment. Which functions need particular attention depends on the extensions, interfaces and custom adjustments used.
A prepared test environment and clear processes make implementation easier. How much time is needed for this, however, can only be estimated on the basis of the respective installation.
Information on our ongoing technical support can be found under Maintenance and support.
Addendum of 8 September 2026: With TYPO3 13.4.35, a further security update has since been released. More on this in our article on version 13.4.35.



