Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Marcus Schwemer

#28304of 56,330
9.5Total CVSS
Vulnerabilities · 1
PT-2026-81236
9.5
2026-08-25
Typo3 · Powermail · CVE-2026-77136
**Name of the Vulnerable Software and Affected Versions** TYPO3 Powermail (affected versions not specified) **Description** An issue exists where the extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as a template source without sanitization. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers, which may lead to the disclosure of server configuration, environment variables, and application source, and potentially result in remote code execution. This issue is reported to be actively exploited in the wild. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.