CVE-2022-47411: Fp Newsletter Project Fp Newsletter

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.

Affected products

  • Fp Newsletter Project Fp Newsletter: before 1.1.1 (fixed in 1.1.1); from 2.0.0, before 2.1.2 (fixed in 2.1.2); from 2.2.1, up to and including 2.4.0; from 3.0.0, before 3.2.6 (fixed in 3.2.6); version 1.2.0 only

Published 2022-12-14. Last modified 2026-06-17.