CVE-2026-77138: TYPO3 Extension HTML5 Video Player Vs. Powermail
Critical severity, CVSS 9.3. EPSS: 0.7% chance of exploitation in the next 30 days.
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
Affected products
- TYPO3 Extension HTML5 Video Player Vs. Powermail: up to and including 0.2.1
Published 2026-08-25. Last modified 2026-09-28.