TYPO3 11.5.37
Release Notes
Release Notes for TYPO3 CMS 11.5.37
This document contains information about TYPO3 CMS 11.5.37 which was released on 14.05.2024.
Get TYPO3 11.5.37 nowNews
This release is a combined bug fix and security release.
Find more details in the security bulletins:
- https://typo3.org/security/advisory/typo3-core-sa-2024-008
- https://typo3.org/security/advisory/typo3-core-sa-2024-009
- https://typo3.org/security/advisory/typo3-core-sa-2024-010
Checksums of TYPO3 11.5.37
SHA256
4a4f70a1f21e4ab04ad6f331f0cb19da0a9c956898de2cacb927a92d8f2bff1e typo3_src-11.5.37.tar.gz fc063fe316f1cc5f21d68b664c6dc8e840c5cc5b5c699091899aa220e4dca21a typo3_src-11.5.37.zip
SHA1
255b575187d7c9e2912bc3c87289f27529dc76ed typo3_src-11.5.37.tar.gz e6db7f60e1008e729a16b52166ad474f3363c1f0 typo3_src-11.5.37.zip
MD5
76396a0f2424ecc70e6e127867623a27 typo3_src-11.5.37.tar.gz 09cb7987a34e0bb65136e7312caa462e typo3_src-11.5.37.zip
Upgrading
The usual upgrading procedure applies. No database updates are necessary. It might be required to clear all caches; the "important actions" section in the TYPO3 Install Tool offers the accordant possibility to do so.
Changes
Here is a list of what was fixed since 11.5.36:
- 2024-05-14 8c01ea0cd9 [RELEASE] Release of TYPO3 11.5.37 (thanks to Oliver Hader)
- 2024-05-14 05c95fed86 [SECURITY] Protect frame GET parameter in tx_cms_showpic eID (thanks to Benni Mack)
- 2024-05-14 376474904f [SECURITY] Encode all file properties in tx_cms_showpic output (thanks to Oliver Hader)
- 2024-05-14 d0393a879a [SECURITY] Prevent XSS in FormManager backend module (thanks to Benjamin Franzke)
- 2024-05-11 87135783a1 [DOCS] Correct example for defining RTE preset of flexform field (thanks to Christian Fries)
- 2024-05-10 f2961dd57a [BUGFIX] Prevent TypeError in DatabaseIntegrityController (thanks to Christoph Lehmann)
- 2024-05-06 e4d7215228 [TASK] Add unicode license file next to .tbl files (thanks to Willi Wehmeier)
- 2024-05-03 21a80869ff [TASK] Update package enshrined/svg-sanitize to 0.18.0 (thanks to Oliver Hader)
- 2024-05-02 123bbfe49c [BUGFIX] Fix PHP Warning in caching framework garbage collection (thanks to Stephan Bauer)
- 2024-04-23 f5bc5558fc [BUGFIX] Avoid mapping route values that are out of scope (thanks to Oliver Hader)
- 2024-04-16 c83bc62b9e [BUGFIX] Cast simulated timestamp to int (thanks to Georg Ringer)
- 2024-04-15 9ce11a7ae4 [BUGFIX] Add missing
resname
attribute to dashboard xlf files (thanks to Andreas Kienast) - 2024-04-10 878373502e [BUGFIX] Set default value for extbase Container::$prototypeObjects... (thanks to Christian Weiske)
- 2024-04-08 e72382d242 [TASK] Add
npm
command dispatcher toBuild/Scripts/runTests.sh
(thanks to Stefan Bürk) - 2024-04-08 6ec3eb49de [BUGFIX] Ensure working count query in
DatabaseRecordList::getTable()
(thanks to Stefan Bürk) - 2024-04-07 f66272ae47 [BUGFIX] Use correct timezones with timestamp based \DateTime (thanks to Markus Klein)
- 2024-04-05 db145c77d2 [BUGFIX] Fix array access error in LinkAnalyzerResult (thanks to Sybille Peters)
- 2024-04-04 9f57120360 [TASK] Avoid calling deprecated Symfony Console helper commands (thanks to Oliver Klee)
- 2024-04-04 dd2dabbf33 [BUGFIX] Fix wrong GUI crop area placement on edge cases (thanks to Andreas Kienast)
- 2024-03-23 f3ee5a5cc3 [TASK] Account for double click pagetree timeout in acceptance tests (thanks to Benjamin Franzke)
- 2024-03-23 95b1f41cd7 [BUGFIX] Admin-only edit lock can be disabled again (thanks to Christian Ludwig)
- 2024-03-22 ee7ef1a314 [TASK] Update core-testing-php image versions (thanks to Stefan Bürk)
- 2024-03-20 f58bceef70 [BUGFIX] Add
_ga
toexcludedParameters
(thanks to Andreas Kienast) - 2024-03-19 318f6ceb28 [TASK] Apply some runTests.sh cleanups (thanks to Benjamin Franzke)
- 2024-03-19 b67a88f6c5 [TASK] Add composer-mode to our acceptance test matrix (thanks to Benjamin Franzke)
- 2024-03-17 b69a1a6f26 [TASK] Fix cache name in comments (thanks to Oliver Klee)
- 2024-03-15 9a28958a1e [TASK] Add GeneralUtility::makeInstance to PHPStorm meta file (thanks to Oliver Bartsch)
- 2024-03-15 eaf9df4220 [TASK] Apply stricter URI route generation assertions (thanks to Oliver Hader)
- 2024-03-12 53024568af [TASK] Limit commit message line length to 72 characters (thanks to Ayke Halder)
- 2024-03-11 c827d1f469 [BUGFIX] Fix FormEngine inline stylesheet resolution in composer mode (thanks to Benjamin Franzke)
- 2024-03-10 951a97c6d7 [DOCS] Put example input in backtics in form manual (thanks to linawolf)
- 2024-03-09 3a7242ac9c [DOCS] Remove unused files in Documentation folder (thanks to linawolf)
- 2024-03-09 d6594305b8 [DOCS] Adjust Includes.rst.txt after switch to PHP-based rendering (thanks to Chris Müller)
- 2024-03-08 012dfb1e70 [BUGFIX] Avoid race condition in DI cache persistence (thanks to Benjamin Franzke)
- 2024-03-08 90c678192b [DOCS] Switch Recycler documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-08 4edf4c1a84 [DOCS] Switch Redirects documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-08 1707c4682c [DOCS] Switch seo documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-08 9e7c2428c0 [DOCS] Switch scheduler documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-08 8252c02c43 [DOCS] Switch workspaces documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-08 3373bb6ce6 [DOCS] Switch rte_ckeditor documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-08 d93e1ff0c2 [DOCS] Fix Edit on GitHub Button for manuals (thanks to linawolf)
- 2024-03-07 e21a76d036 [BUGFIX] Do not try to log negative UID in DataHandler (thanks to Markus Klein)
- 2024-03-07 7deb146ef9 [BUGFIX] Exclude
gbraid
andwbraid
parameters from cHash calculation (thanks to Daniel H) - 2024-03-07 52e4a24091 [DOCS] Switch linkvalidator documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-07 c9e0a43b48 [DOCS] Switch Indexed Search documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-07 04fd8a2e93 [DOCS] Switch impexp documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-07 dfa0654676 [DOCS] Switch felogin documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-07 bb7a553a49 [DOCS] Switch fluid_styled_content documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-07 8830806383 [DOCS] Fix references in admin panel (thanks to Chris Müller)
- 2024-03-07 eaa7c1be12 [DOCS] Add regex example to target column referencing capturing groups (thanks to Josef Glatz)
- 2024-03-06 e4bc8ee4f1 [BUGFIX] Cast DOM attribute values to string (thanks to Helmut Hummel)
- 2024-03-06 bd75219155 [DOCS] Switch Dashboard documentation to PHP-based rendering (thanks to linawolf)
- 2024-03-05 a598d0c28e [TASK] Allow execution of acceptance tests with local chromedriver (thanks to Benjamin Franzke)
- 2024-03-04 d9a4e39558 [BUGFIX] Exclude
gad_source
parameter from cHash calculation (thanks to Andreas Kienast) - 2024-03-03 7a130c0f4f [DOCS] Switch adminpanel docs to PHP-based rendering (thanks to linawolf)
- 2024-02-28 2319103e7d [BUGFIX] Allow maxitems=1 for TCA type category (thanks to Markus Klein)
- 2024-02-23 4e44ae83ee [BUGFIX] Prevent possible browser freezes in FormEditor (thanks to Benjamin Franzke)
- 2024-02-22 792fb2ba83 [TASK] Prevent undefined encryptionKey in tests (thanks to Torben Hansen)
- 2024-02-22 90cb7cffd2 [TASK] Use correct command dispatch in
runTests.sh
(thanks to Stefan Bürk) - 2024-02-21 c4b58ae45c [BUGFIX] Avoid notice in template module by an early return (thanks to Georg Ringer)
- 2024-02-21 d6146559fc [TASK] Add better PHPStan annotation for method getRepositoryClassName (thanks to sschreiberten)
- 2024-02-20 76b20cc900 [TASK] Set TYPO3 version to 11.5.37-dev (thanks to Benni Mack)