Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ingrid Stürmer

#23418of 56,337
10.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-81231
5.3
2026-08-25
Typo3 · Extension "Syssy - Typo3 Monitoring & Security Checks" · CVE-2026-77130
**Name of the Vulnerable Software and Affected Versions** The product name cannot be determined (affected versions not specified) **Description** The extension fails to properly validate the expiration of a client-supplied JWT (JSON Web Token), which is a compact, URL-safe means of representing claims to be transferred between two parties. This flaw allows an attacker who possesses a valid API key to authenticate using an expired token. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-81232
5.3
2026-08-25
Typo3 · Typo3 · CVE-2026-77131
**Name of the Vulnerable Software and Affected Versions** The product name cannot be determined (affected versions not specified) **Description** When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation of this issue requires the attacker to already have control of the SYSSY project's API key. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.