Fri. 11th November, 2016
It has been discovered that the extension "TC Directmail " (tcdirectmail) is susceptible to Cross Site-Scripting and SQL Injection.
This is a companion discussion topic for the original entry at https://typo3.org/article/typo3-ext-sa-2016-026