Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4280 articles · 196875 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77136KEVEXPLOITEDPATCHED
typo3 · extension "powermail"

Server-Side Template Injection in extension "powermail" (powermail)

Description

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. Exploitation requires only that a form field is configured as the sender_name field, a common and default-adjacent Powermail configuration. No authentication or user interaction beyond a normal form submission is required. This vulnerability is reported to be actively exploited in the wild.

Affected Products

VendorProductVersions
typo3extension "powermail"13.0.0, 11.0.0, 0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-022(vendor-advisory)

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-77136 | TYPO3 Powermail up to 10.9.2/12.6.0/13.2.0 Fluid View sender_name code injection
→ No new info (linked only)
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
13.2.112.6.110.9.3
CWECWE-1336
PublishedAug 25, 2026
Trending Score92
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
Trending: 34
NONECVE-2026-77143
Broken Access Control in extension "Forum" (pforum)
Trending: 30
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 30
NONECVE-2026-77140
Broken Access Control in extension "Telephone Directory" (telephonedirectory)
Trending: 30
NONECVE-2026-56095
Insecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
Trending: 25

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Added to CISA KEV
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Actively Exploited
Aug 25, 2026
Patch Available
Aug 25, 2026