Input Validation Flaw in TYPO3 Extension Allows Unauthorized Data Disclosure
CVE-2026-77129

7.7HIGH

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77129?

An input validation vulnerability exists in the TYPO3 Event Registration Plugin that allows authenticated backend users with edit access to pass an editor-configurable email subject string directly into a Fluid template without restriction. This flaw enables the injection of Fluid ViewHelper syntax, potentially disclosing sensitive information or executing TypoScript content objects. Exploiting this vulnerability necessitates having an account with edit permissions, which highlights the need for stringent access control and validation mechanisms.

Affected Version(s)

Extension "Event management and registration" 9.0.0 < 9.0.3

Extension "Event management and registration" 8.0.0 < 8.6.2

Extension "Event management and registration" 7.0.0 < 7.9.3

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Torben Hansen
.