VYPR

TYPO3 extension

by TYPO3

CVEs (1)

  • CVE-2026-46725CriMay 19, 2026
    risk 0.60cvss epss 0.03

    The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3…