TYPO3 CMS Event Reg Ext. XSS via unchecked Fluid subject
CVE-2026-77129 Published on August 25, 2026
Server-Side Template Injection in extension "Event management and registration" (sf_event_mgt)
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.
Vulnerability Analysis
CVE-2026-77129 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Affected Versions
TYPO3 Extension "Event management and registration":- Version 9.0.0 and below 9.0.3 is affected.
- Version 8.0.0 and below 8.6.2 is affected.
- Version 7.0.0 and below 7.9.3 is affected.
- Version 6.0.0 and below 6.7.2 is affected.
- Before 5.9.3 is affected.