NONE · 0

CVE-2026-77129

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can su...

Vulnerability Description

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-77129?

CVE-2026-77129 is a documented vulnerability. The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can su...

How severe is CVE-2026-77129?

CVSS scoring is not yet available for CVE-2026-77129. Check NVD for updates.

Is there a patch for CVE-2026-77129?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.