VYPR

typo3-ext-sa-2026-011

by TYPO3

Source repositories

CVEs (3)

  • CVE-2026-77134HigAug 25, 2026
    risk 0.54cvss —epss 0.00

    The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting…

  • CVE-2026-77128MedAug 25, 2026
    risk 0.41cvss —epss 0.01

    The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this…

  • CVE-2026-46722MedMay 19, 2026
    risk 0.38cvss —epss 0.00

    The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search…