[NEW] [critical] TYPO3 Extensions: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in various TYPO3 Extensions to execute arbitrary code, perform SQL injection, gain elevated privileges, manipulate data, disclose sensitive information, bypass security measures, or trigger a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in various TYPO3 Extensions allow remote code execution, SQL injection, privilege escalation, data manipulation, information disclosure, security bypass, and denial-of-service attacks.
- Who is affected
- All deployments using affected TYPO3 Extensions without patch versions applied.
- Urgency
- Critical; unpatched extensions expose systems to immediate compromise including arbitrary code execution and data breach.
- Action
- Identify and update all affected TYPO3 Extensions to patched versions immediately; consult TYPO3 extension repository for CVE-specific remediation versions.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3003
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-560920.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-560930.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-560940.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-560950.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-560960.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771270.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771280.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771290.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771300.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771310.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-77146: The extension's invitation controller fails to stop processing after redirecting on invalid in…nvd
- unknownCVE-2026-77142: The frontend company self-service editing feature relies on a template-level visibility flag t…nvd
- unknownCVE-2026-77141: The extension resolves the targeted club record from a user-supplied request argument in its f…nvd
- unknownCVE-2026-77140: The extension validates the HMAC of a frontend employee edit link only in the action that rend…nvd
- unknownCVE-2026-77139: The extension fails to validate a client-supplied template element key before using it to buil…nvd
- unknownCVE-2026-77138: The extension fails to safely process untrusted client input of an attacker-controlled cookie …nvd
- unknownCVE-2026-77137: The extension fails to properly sanitize user input before using it in a database query. As a …nvd
- unknownCVE-2026-77136: The extension passes the raw value of a form field configured as "This field contains the name…nvd
- unknownCVE-2026-77135: The extension's user detail view fails to verify that a requested user record matches the conf…nvd
- unknownCVE-2026-77134: The extension fails to require the dedicated admin confirmation token when processing an admin…nvd
- unknownCVE-2026-77133: The extension fails to restrict which frontend usergroups a logged-in user may assign to their…nvd
- unknownCVE-2026-77131: When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in…nvd
Recent advisories for TYPO3 Extensions
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Red Hat Enterprise Linux (assertj): Vulnerability allows information disclosure and DoS2026-08-26
- medium[NEW] [medium] GNU Emacs: Vulnerability allows information disclosure and DoS2026-08-26
- medium[NEW] [medium] vllm: Multiple vulnerabilities2026-08-26
- high[NEW] [high] Veeam ONE: Multiple Vulnerabilities2026-08-26
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25