VYPR

SYSSY - TYPO3 Monitoring & Security Checks

by TYPO3

CVEs (2)

  • CVE-2026-77131MedAug 25, 2026
    risk 0.34cvss epss

    When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

  • CVE-2026-77130MedAug 25, 2026
    risk 0.34cvss epss

    The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.