TYPO3-CORE-SA-2023-001: Persisted Cross-Site Scripting in Frontend Rendering

TYPO3-PSA-2023-001: Important Security-Bulletin Pre-Announcement

The TYPO3 Security Team pre-announces an important security release.

The CVSS implies the vulnerability can be exploited remotely, without privileges and with low complexity. I think this makes it clear that admins will be in a race with attackers tomorrow.
