Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4280 articles · 196875 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77138PATCHED
typo3 · extension "html5 video player vs. powermail"

Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)

Description

The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.

Affected Products

VendorProductVersions
typo3extension "html5 video player vs. powermail"0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-014(vendor-advisory)

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-77138 | TYPO3 HTML5 Video Player vs. Powermail Plugin up to 0.2.1 unserialize cookie deserialization
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://typo3.org/security/advisory/typo3-ext-sa-2026-014
CWECWE-502
PublishedAug 25, 2026
Trending Score34
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77136EXPKEV
Server-Side Template Injection in extension "powermail" (powermail)
Trending: 92
NONECVE-2026-77143
Broken Access Control in extension "Forum" (pforum)
Trending: 30
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 30
NONECVE-2026-77140
Broken Access Control in extension "Telephone Directory" (telephonedirectory)
Trending: 30
NONECVE-2026-56095
Insecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
Trending: 25

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026