CVE-2026-77141: TYPO3 Extension Club Directory
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to the update or activate action and overwrite that record, or publish one still awaiting approval, without owning it.
Affected products
- TYPO3 Extension Club Directory: from 8.0.0, before 8.1.3 (fixed in 8.1.3); from 7.0.0, before 7.0.2 (fixed in 7.0.2); before 6.0.2 (fixed in 6.0.2)
Published 2026-08-25. Last modified 2026-09-28.