CVE-2026-77135: TYPO3 Extension Femanager
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
Affected products
- TYPO3 Extension Femanager: from 13.0.0, before 13.3.5 (fixed in 13.3.5); from 8.0.0, before 8.4.2 (fixed in 8.4.2); from 7.0.0, before 7.5.5 (fixed in 7.5.5); before 6.4.5 (fixed in 6.4.5)
Published 2026-08-25. Last modified 2026-09-28.