Input Validation Flaw in TYPO3 Extension Allows Unauthorized Data Disclosure
CVE-2026-77129
7.7HIGH
Key Information:
- Vendor
Typo3
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-77129?
An input validation vulnerability exists in the TYPO3 Event Registration Plugin that allows authenticated backend users with edit access to pass an editor-configurable email subject string directly into a Fluid template without restriction. This flaw enables the injection of Fluid ViewHelper syntax, potentially disclosing sensitive information or executing TypoScript content objects. Exploiting this vulnerability necessitates having an account with edit permissions, which highlights the need for stringent access control and validation mechanisms.
Affected Version(s)
Extension "Event management and registration" 9.0.0 < 9.0.3
Extension "Event management and registration" 8.0.0 < 8.6.2
Extension "Event management and registration" 7.0.0 < 7.9.3
