TYPO3 update

TYPO3 upgrade to v14 LTS

TYPO3 v14 LTS has been the current long-term version since 21 April 2026; the current releases are 14.3.6 and 13.4.34. If you are still on v12 or older, security updates now cost money — or are no longer available at all. We are Sharpness Solutions, a digital agency in Oldenburg, Lower Saxony, and we carry out TYPO3 upgrades across Germany, remotely as well, and on systems somebody else built. Below you will find the support end dates, the ELTS prices, the breaking changes in v14 and how an upgrade runs.

Make an enquiry 0441 21 21 63 0 Mo – Fr, 9:00 – 16:00 Uhr

What you are dealing with right now

Most enquiries about TYPO3 updates are not driven by enthusiasm for new features. They arrive because somebody found a deadline, because a tender is coming up, because a security audit has run, or because the old agency has stopped answering. W3Techs publishes shares by TYPO3 major version (retrieved 16 August 2026). Versions 13 and 14, the two still receiving free support, account for 26.0 percent between them; version 12 and older make up the remaining 74 percent or so. The basis is the TYPO3 sites recorded by W3Techs whose major version could be determined; W3Techs does not state how large that share is of all TYPO3 installations. About the rest, the figure says nothing. You are not in bad company. You are unprotected all the same.

You do not know which version is actually running

The TYPO3 version number sits at the bottom of the module bar in the backend, and in more detail under Admin Tools → Environment; in v14 that area is called Administration → Environment. Without backend access it gets difficult: since TYPO3 6.2 the meta generator in the source code only says “TYPO3 CMS” and no longer names a version.

Your version no longer receives security updates

Free support for TYPO3 v12 ended on 30 April 2026, for v11 on 31 October 2024, for v10 on 30 April 2023. For v9 and v8 there is no purchasable ELTS (Extended Long Term Support) either, since 30 September 2025 and 31 March 2024 respectively.

You have to put a number in the budget

Management wants a figure for the budget. Five things drive the effort: the version you start from, the number of in-house extensions, the share of plugins registered via list_type, the interfaces, and the state of the frontend. You can count the first four yourself. The state of the frontend needs an outside assessment.

The agency that built it is no longer reachable

No Composer setup, no repository, a server nobody has access to any more: that is the normal case for systems that have been running for ten years. Most of it can be reconstructed. That work then belongs in the estimate.

Upgrade, or rebuild straight away?

From TYPO3 v8 or v9, an upgrade is technically a rebuild with the data carried over. The upgrade wizards for older versions left the core long ago. If the frontend is outdated as well, rebuilding often costs less than the rescue attempt.

Accessibility — if you sell to consumers

The German Accessibility Improvement Act (Barrierefreiheitsstärkungsgesetz, BFSG) has applied to consumer offerings in electronic commerce since 28 June 2025. Pure B2B is not covered, and for services there is a micro-enterprise exemption. If it does apply to you: accessibility cannot sensibly be retrofitted to a neglected system. Then both topics belong in one project, not two.

What happens without security updates

A TYPO3 instance without security updates is not inconspicuous. It is documented as vulnerable. On 9 June 2026 the TYPO3 Security Team published 14 core advisories at once — TYPO3-CORE-SA-2026-006 through -019, among them broken access control, cross-site scripting, open redirect, insecure deserialisation and SQL injection. The fixes appeared as 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS and 14.3.3 LTS. Anyone running v10, v11 or v12 without a paid ELTS contract still has exactly these holes open today. The flaw is publicly described, the patch exists. It sits behind an invoice. You can read all of it in the security advisories on typo3.org.

One example to quote in the decision paper: TYPO3-CORE-SA-2026-008, CVE-2026-47346, severity High, published on 9 June 2026. Backend users with write access to files could upload form definitions with mixed upper and lower case in the file name, use that to bypass the Form Framework's upload restriction, and run arbitrary SQL statements through prepared definitions — up to creating administrator accounts of their own. Affected were 10.0.0 to 10.4.56, 11.0.0 to 11.5.50, 12.0.0 to 12.4.45, 13.0.0 to 13.4.30 and 14.0.0 to 14.3.2. Five months earlier, on 13 January 2026, TYPO3-CORE-SA-2026-003 (CVE-2025-59022) let backend editors with Recycler access delete arbitrary records from any TCA table — including tables they had no rights to.

Outdated TYPO3 installations do get attacked in practice, and a hit often goes unnoticed for a long time. In March 2014 heise online reported hundreds of compromised TYPO3 websites, many of them in Germany, running on the LTS of the day, 4.5.x: PHP files in the configuration directory, a main.php in the web root, a manipulated .htaccess that served casino spam only to visitors arriving from search engines. Direct requests got an error page. The operators noticed nothing. Whether a TYPO3 vulnerability was the way in was never established: the TYPO3 Association contradicted the account at the time, and sites without TYPO3 were affected as well. That is exactly the point. On a neglected system you cannot reconstruct afterwards what happened. Then there is the second layer: anyone running TYPO3 v8, v9 or v10 is necessarily on PHP 7.4 or older. PHP 7.4 has been end of life since 28 November 2022. The gap is then in the application and in the runtime environment at the same time.

Support end dates and ELTS: the numbers

TYPO3 v14 LTS was released on 21 April 2026 and receives free support until 30 June 2029, ELTS until 30 June 2032. TYPO3 v13 LTS: free until 31 December 2027, ELTS until 31 December 2030. v12: free support ended on 30 April 2026, ELTS runs to 30 April 2030, the fourth of those years only through TYPO3 partners. v11: free support ended on 31 October 2024, regular ELTS to 31 October 2027, the fourth year to 31 October 2028 only through TYPO3 partners. v10: free support ended on 30 April 2023, regular ELTS to 30 April 2026 — the fourth year to 30 April 2027 can be booked exclusively through TYPO3 partners. So if you are on v10 today, that is the only remaining route to ELTS. v9.5: ELTS expired on 30 September 2025. v8.7: ELTS expired on 31 March 2024. For v9 and older there are no security updates at all any more, not even for money.

ELTS (Extended Long Term Support) is the paid security support the TYPO3 GmbH provides for versions whose free support has run out. A single licence (“Single Plan”) for TYPO3 v12 has cost 3,200 euros per year before discounts since April 2026; for v11 and v10 the list price is 2,800 euros. One licence covers one instance: a single TYPO3 installation together with its live, failover, staging and development environments, even when several websites run on it. Several independent installations need several licences. Members of the TYPO3 Association get 25 percent (Silver), 30 percent (Gold) or 45 percent (Platinum) off. Three points belong with that. ELTS delivers security and compatibility patches only, no features. The fourth ELTS year in each case — for v12 to 30 April 2030, for v11 to 31 October 2028, for v10 to 30 April 2027 — is available exclusively through TYPO3 Solution and Technology Partners. And the matching PHP version runs out in parallel: TYPO3 v12 is released for PHP 8.1 to 8.4. PHP 8.1 has had no security updates since 31 December 2025, PHP 8.2 only until 31 December 2026 — so the runtime environment has to be brought forward separately. An ELTS contract for TYPO3 does not cover the runtime environment.

Whether ELTS or an upgrade is cheaper is decided by the timeframe. Three years of v12 ELTS add up to 9,600 euros in licence costs before discount, and at the end of it not a single breaking change has been dealt with. On 30 April 2029 you are standing in the same place, only with three more years of technical distance to the target version. ELTS still has its uses: as a bridge when a relaunch is already scheduled, when a certification or tender period is running, or when there is simply no project budget left in the current financial year. As a permanent arrangement it is expensive. We clarify the procurement route beforehand: for TYPO3 v10 and v11 it runs through a TYPO3 partner. The end dates and prices in this section come from get.typo3.org and typo3.com/elts, retrieved on 16 August 2026.

What breaks technically in v14

The point at which most existing systems break in TYPO3 v14 is called list_type. The database field tt_content.list_type and the content element tt_content.list have been removed without replacement (Breaking #105377). Classic plugin registration via CType=list therefore no longer works: ExtensionUtility::configurePlugin() now registers plugins as their own CType, and the parameter for the plugin sub-type has become ineffective and can be dropped — any value other than CType raises an exception. In ExtensionManagementUtility::addPlugin() the arguments $type and $extensionKey have been removed without replacement. Every affected extension also needs an upgrade wizard of its own, inheriting from AbstractListTypeToCTypeUpdate, that maps old list_type values onto new CType values. Extensions without that wizard leave behind content elements after the upgrade that nothing renders any more.

Besides list_type, TYPO3 v14 breaks the rendering layer in ways that touch every custom template. The TypoScriptFrontendController is gone (#107831), as is the TypoScript condition getTSFE() (#107473). Fluid 5.0 brings strict types in ViewHelpers and changed CDATA behaviour (#108148). TYPO3's own Fluid views TYPO3\CMS\Fluid\View\StandaloneView, \TemplateView and \AbstractTemplateView have been removed; views are now created through ViewFactoryInterface::create(). Add to that the Extbase class HashService and methods such as GeneralUtility::hmac() or ExtensionManagementUtility::addPageTSConfig(). Callables in TypoScript and TSconfig need an opt-in via the attribute #[AsAllowedCallable] (#108054). Asset concatenation in the frontend (#108055) and HTTP response compression (#107943) have been dropped; both now belong in the build process and the web server.

A good part of the breaking changes in TYPO3 v14 can be migrated automatically, but not all of them. For the v14 migration, 45 new Rector rules and 11 new Fractor rules were funded from the TYPO3 community budget: Rector migrates PHP code, Fractor the remaining files — TypoScript, FlexForms, YAML, Fluid templates. The Extension Scanner in the Install Tool finds calls to removed API in your own code. Manual work remains wherever a third-party extension has no v14 release, wherever business logic sits in templates, and wherever libraries collide over Composer constraints. Nonsense that is cleanly implemented is still nonsense, even after the Rector run.

Upgrade, v13 as an interim step, or rebuild

Whether an existing TYPO3 system is taken to v14, lifted to v13 first, or rebuilt with the data carried over, is decided by four thresholds — not by instinct. First, the version you start from: from TYPO3 v12 or v13, v14 is an ordinary upgrade project. From v11 it is two jumps with a stop in between. TYPO3 removes upgrade wizards from the core two major versions after they were introduced; for data from v10 and older they are therefore missing in v14, and have to be made up through an intermediate version or a community extension. Second, the number of in-house extensions. Third, the share of plugins registered via list_type. Fourth, the state of the frontend: if the design is going to be replaced anyway, there is no reason left to rescue the old template.

An upgrade from TYPO3 v8 or v9 to v14 is technically a rebuild with the data carried over, not a version jump. Between v9.5 and v14 lie five major versions, the move from PHP 7.2 to PHP 8.2, and with Composer a different operating model. The new code has to be written either way; what comes across is content, page structure, files and URLs. And when the page structure has grown over the years on top of that, and nobody can still explain why there are three news sections, rebuilding is the cheaper answer. The estimate puts both routes side by side with both figures, even though the upgrade is the smaller job.

The target version is normally TYPO3 v14; v13 as an interim step only with a reason. v13 gets free support until 31 December 2027, v14 until 30 June 2029 — going to v13 in 2026 means booking the next upgrade for 2027. Exactly one argument speaks for v13: the list_type requirement does not apply there yet. If a business-critical third-party extension has no v14 release and no replacement is in sight, v13 is the dependable intermediate step. Otherwise the detour costs two rounds of testing for the same result.

What changes for editors and for operations

The TYPO3 v14 backend has been redesigned: revised styling, simplified navigation, renamed modules. Your editors will notice that more than anything else in the project. Content elements are edited in the context panel without the page reloading completely. New pages are created through a guided assistant, translations likewise. And the module tree is named differently — in the first week that costs the editorial team more time than any new function. Plan for a short briefing, an hour on the test system, before you switch over, not afterwards.

For operations and administration, TYPO3 v14 brings Redis support for Install Tool sessions — until now these were tied to local files, which regularly caused trouble in multi-server and container setups — plus Redis authentication with username and password. Redis backends for frontend and backend sessions have existed since v8. Also new are a content type usage report across sites, and setting the Install Tool password from the command line. The system requirements are specific: PHP from 8.2.0 to 8.5.99, Composer from 2.1, at least 256 MB of RAM, MariaDB from 10.4.3, MySQL from 8.0.17, PostgreSQL from 10.0 or SQLite from 3.8.3. From v14.0 a valid composer.json is mandatory for every extension, explicitly including Classic Mode installations.

After the upgrade comes the part where most projects fail: maintenance. The TYPO3 maintenance plan schedules maintenance releases roughly every four weeks; for v14 the dates from 14.3.1 on 12 May 2026 to 14.3.21 on 14 December 2027 have been published. That is around 13 predictable update windows a year, plus the unpredictable security releases. If you do not plan for them, in four years you will be standing in front of the same question. If you would rather not work the windows yourself, hand them over to us: 13 planned dates a year plus the unplanned ones, governed by an SLA.

Process

We will look at your TYPO3.

Send us the version number, the extension list, or simply the URL. You get a written assessment with target version, risk position and a range for the work involved — even if you go on to commission somebody else. Sharpness Solutions GmbH, Edewechter Landstraße 161, 26131 Oldenburg, Germany. Telephone +49 441 21 21 63 0, Monday to Friday, 9:00 to 16:00 CET, info@sharpness.de.

  1. 1

    Taking stock

    In the first step we go through access credentials, repository, server environment and database. We establish the running TYPO3 version, the PHP and database version, the Composer status and the list of all installed extensions. If the source code is missing, we reconstruct it from the server. You get the result in writing. Duration: a few working days.

  2. 2

    Extension audit

    We assess each extension on its own. Is there a v14 release? Does it bring an upgrade wizard for list_type? Is it still in use at all? Is there a replacement, or does the function have to be rebuilt? In parallel, the Extension Scanner checks your own code. The effort grows with the number of extensions.

  3. 3

    Decision and estimate

    Before the first line of code there is a result: an upgrade across the LTS steps, v13 as an interim target, or a rebuild with the data carried over. With it an estimate broken down by trade, a fixed price for the clearly delimited parts, and a named list of the points that can only be decided on the test system.

  4. 4

    Test instance and step-by-step upgrade

    The work happens on a copy; your website stays live. The jump runs across the LTS steps, not in one go: each step with a database compare, upgrade wizards and a functional test. Rector and Fractor run alongside, the rest is manual work. This is the longest block in the project.

  5. 5

    Acceptance, editor briefing, go-live

    You test on the staging system against an acceptance list: forms, search, interfaces, editorial workflow, redirects. Before that the editorial team gets a briefing on the new backend. The go-live runs in the agreed window, usually outside business hours and as a rule in under two hours, with a complete backup and a documented way back.

  6. 6

    Follow-up and maintenance

    After go-live come monitoring of the logs, the follow-up work from the acceptance list and the handover of the documentation. Then the question of who works the roughly 13 predictable update windows a year from now on — you or us, under an SLA.

Projects on this system

A selection — not the full client list.

Frequently asked questions

How long will my TYPO3 version keep getting security updates?

As of 16 August 2026, free support exists only for TYPO3 v13 (until 31 December 2027) and v14 (until 30 June 2029). For v12 it ended on 30 April 2026, for v11 on 31 October 2024, for v10 on 30 April 2023. Those three versions can still be covered by paid ELTS: v10 until 30 April 2027, v11 until 31 October 2028, v12 until 30 April 2030 — in each case the final year only through a TYPO3 partner, and for v10 that final year is the period we are in right now. For v9.5 and v8.7, ELTS has expired as well.

How do I find out which TYPO3 version I am running?

The TYPO3 version number sits at the bottom of the module bar in the backend, and in full under Admin Tools → Environment → Environment Overview; in v14 that area is called Administration → Environment. Over SSH the command line is the most reliable route: vendor/bin/typo3 --version in the project directory, or typo3/sysext/core/bin/typo3 --version for Classic Mode installations. Without access the version cannot be determined seriously from outside: since TYPO3 6.2 the generator tag no longer contains a version number, and online checks work with fingerprints that come up empty depending on the configuration.

What does a TYPO3 upgrade cost?

A TYPO3 upgrade is priced by the work involved, and five factors decide how much work that is: the version you start from, the number of in-house extensions, the share of plugins registered via list_type, the interfaces to other systems, and the state of the frontend. Four of them you can count yourself — the version under Admin Tools → Environment, the in-house extensions in packages/ or typo3conf/ext/, the plugins in the tt_content.list_type field, the interfaces from your systems list. A jump from v12 to v14 is, in order of magnitude, a project of weeks; a rebuild from v9 or older one of months. After the extension audit there is a fixed price for the delimited parts.

How long does a TYPO3 upgrade to v14 take?

An upgrade from TYPO3 v12 to v14 is a project of weeks where the extension inventory is manageable; a rebuild from v9 with the data carried over is one of months. The pace is set by taking stock and by the extension audit at the start, by the availability of v14 releases for third-party extensions in the middle, and by your approvals at the end. The longest block is the step-by-step upgrade across the LTS versions. The switchover window at go-live itself is usually under two hours.

What is TYPO3 ELTS and what does it cost?

ELTS (Extended Long Term Support) is the paid security support the TYPO3 GmbH provides for versions whose free support has run out; it delivers security and compatibility patches, not features. A single licence for TYPO3 v12 has cost 3,200 euros per year before discounts since April 2026; for v11 and v10 the maximum price is 2,800 euros. Members of the TYPO3 Association receive 25, 30 or 45 percent off. Three years of v12 ELTS cost 9,600 euros before discount and solve no technical problem. What you buy is time until a scheduled relaunch.

Can I jump straight from TYPO3 v9 to v14?

A direct jump from TYPO3 v9 to v14 is technically possible, but in practice it is a rebuild with the data carried over, not an upgrade. TYPO3 removes upgrade wizards from the core two major versions after they were introduced, so for data from v10 and older they are missing in v14. Between v9.5 and v14 lie five major versions, the move from PHP 7.2 to at least PHP 8.2, and the switch to Composer. Content, page structure, files and URLs come across; the code is written anew.

Do content, URLs and Google rankings survive the upgrade?

Content, page structure and files are carried over in the upgrade, and URLs stay intact as long as the routing configuration comes with them. Rankings depend on URLs, content, loading time and internal linking, not on the TYPO3 version. It gets critical when the page structure is changed in the same step: then every old URL needs a 301 redirect, and that belongs on the acceptance list. Restructure without redirects and you lose visibility — not because of the upgrade, but because of the missing redirects.

Is the website offline during the upgrade?

No, your website stays online during the TYPO3 upgrade: the work happens on a copy of the system while the production instance keeps running unchanged. The site is offline only during the switchover window at go-live, usually outside business hours and as a rule under two hours. A complete backup of database and files is taken immediately beforehand, so that the way back to the old state is documented and rehearsed. Content the editorial team creates during the rebuild phase we bring across before the switchover.

What happens to extensions that no longer exist for v14?

For TYPO3 extensions without a v14 release there are three routes: replacement by a maintained alternative, taking the code over and maintaining it yourself, or rebuilding the function. Which route is cheaper is decided by the scope of the function, not by fondness for the extension. The list_type point matters here: extensions without an upgrade wizard based on AbstractListTypeToCTypeUpdate leave behind content elements after the upgrade that are no longer rendered. Standard extensions move on too — from version 14.0.0, news no longer supports TYPO3 v12.

Is a web application firewall enough to secure an outdated TYPO3 version?

A web application firewall reduces the risk but does not remove it. It filters known attack patterns; vulnerabilities such as TYPO3-CORE-SA-2026-003, where authenticated backend users could delete other people's records through the Recycler module, travel over legitimate requests and are not recognised. Second, a v8, v9 or v10 instance necessarily runs on PHP 7.4 or older, which itself has had no security updates since 28 November 2022. A web application firewall buys time for a scheduled upgrade. As a permanent state it replaces no patch.

Does TYPO3 v14 meet the requirements of the BFSG automatically?

No, TYPO3 v14 does not satisfy the German Accessibility Improvement Act (BFSG) automatically — the BFSG has applied since 28 June 2025 and judges the result in the frontend, not the CMS version. The yardsticks are EN 301 549 and WCAG level AA; what counts are templates, contrast, focus order, forms and editorial practice. A current TYPO3 makes the implementation possible, no more than that. Covered are consumer offerings in electronic commerce; pure B2B is in principle outside the scope, and for services there is a micro-enterprise exemption below 10 employees and no more than 2 million euros in turnover. Whether you are covered is for your legal advisers to determine.

Do you also take on TYPO3 systems that another agency built?

Yes, we take on TYPO3 systems that another agency built — with upgrade enquiries that is the normal case. For the analysis we need backend access with administrator rights, SSH or FTP access to the server, database access and, if it exists, the repository. If the source code or the Composer setup is missing, we reconstruct the state from the server; that work then belongs in the estimate. After that we take on the system including documentation and ongoing maintenance.

Enquiry

We will look at your TYPO3.

Send us the version number, the extension list, or simply the URL. You get a written assessment with target version, risk position and a range for the work involved — even if you go on to commission somebody else.

  • An answer from someone who knows the system — no phone queue
  • An assessment before the quote, even when it advises against the project
  • Your details are sent to us by email, not into a third-party CRM

Spam protection: Cloudflare Turnstile — no cookies, no tracking.

Call Start a project