CVE-2026-77128: TYPO3 Extension Event Management And Registration
Medium severity, CVSS 6.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.
Affected products
- TYPO3 Extension Event Management And Registration: from 9.0.0, before 9.0.3 (fixed in 9.0.3); from 8.0.0, before 8.6.2 (fixed in 8.6.2); from 7.0.0, before 7.9.3 (fixed in 7.9.3); from 6.0.0, before 6.7.2 (fixed in 6.7.2); before 5.9.3 (fixed in 5.9.3)
Published 2026-08-25. Last modified 2026-08-26.