CVE-2026-77129
Received Received - Intake

Fluid Template Injection in TYPO3 Event Registration Extension

Vulnerability report for CVE-2026-77129, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TYPO3

Description

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
typo3 sf_event_mgt to 5.9.3 (exc)
typo3 sf_event_mgt From 6.0.0 (inc) to 6.7.2 (exc)
typo3 sf_event_mgt to 6.7.2 (exc)
typo3 sf_event_mgt From 7.0.0 (inc) to 7.9.3 (exc)
typo3 sf_event_mgt to 7.9.3 (exc)
typo3 sf_event_mgt From 8.0.0 (inc) to 8.6.2 (exc)
typo3 sf_event_mgt to 8.6.2 (exc)
typo3 sf_event_mgt From 9.0.0 (inc) to 9.0.3 (exc)
typo3 sf_event_mgt to 9.0.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an extension that allows an authenticated backend user with edit access to inject Fluid ViewHelper syntax into an email subject field. This can lead to sensitive data disclosure or execution of TypoScript content objects.

Detection Guidance

Check for unauthorized Fluid ViewHelper syntax in email subject fields of the event registration plugin or backend module. Review logs for suspicious template injections or data disclosures.

Impact Analysis

An attacker with backend access could exploit this to read sensitive data or run malicious code, potentially compromising the system or leaking confidential information.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating GDPR or HIPAA requirements for data protection and confidentiality.

Mitigation Strategies

Restrict edit access to the event plugin and backend module to trusted users only. Sanitize email subject inputs to block Fluid ViewHelper syntax. Update the extension to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77129. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart