Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4280 articles · 196875 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77129PATCHED
typo3 · extension "event management and registration"

Server-Side Template Injection in extension "Event management and registration" (sf_event_mgt)

Description

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.

Affected Products

VendorProductVersions
typo3extension "event management and registration"9.0.0, 8.0.0, 7.0.0, 6.0.0, 0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-023(vendor-advisory)

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-77129 | TYPO3 Event management and registration Plugin up to 9.0.2 information disclosure
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
9.0.38.6.27.9.36.7.25.9.3
CWECWE-1336
PublishedAug 25, 2026
Trending Score25
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77136EXPKEV
Server-Side Template Injection in extension "powermail" (powermail)
Trending: 92
NONECVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
Trending: 34
NONECVE-2026-77143
Broken Access Control in extension "Forum" (pforum)
Trending: 30
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 30
NONECVE-2026-77140
Broken Access Control in extension "Telephone Directory" (telephonedirectory)
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026