TYPO3 CMS Event Reg Ext. XSS via unchecked Fluid subject
CVE-2026-77129 Published on August 25, 2026

Server-Side Template Injection in extension "Event management and registration" (sf_event_mgt)
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-77129 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

CWE-1336

Affected Versions

TYPO3 Extension "Event management and registration":