VYPR

femanager

by TYPO3

CVEs (4)

  • CVE-2026-77146HigAug 25, 2026
    risk 0.54cvss epss

    The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account.…

  • CVE-2026-77134HigAug 25, 2026
    risk 0.54cvss epss

    The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting…

  • CVE-2026-77135HigAug 25, 2026
    risk 0.53cvss epss

    The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and…

  • CVE-2026-77133MedAug 25, 2026
    risk 0.39cvss epss

    The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.