CVE-2026-8827: TYPO3 Extension Address List

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call this method with untrusted input would expose the site to SQL injection.

Affected products

  • TYPO3 Extension Address List: from 10.0.0, before 10.0.1 (fixed in 10.0.1); from 9.0.0, before 9.1.1 (fixed in 9.1.1); before 8.1.2 (fixed in 8.1.2)

Published 2026-05-19. Last modified 2026-06-17.