๐Ÿ” CVE Alert

CVE-2026-77138

UNKNOWN 0.0

Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.

CWE CWE-502
Vendor typo3
Product extension "html5 video player vs. powermail"
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 extension "html5 video player vs. powermail"

Be the first to know when new unknown vulnerabilities affecting typo3 extension "html5 video player vs. powermail" are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / Extension "HTML5 Video Player vs. Powermail"
0 โ‰ค 0.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-ext-sa-2026-014

Credits

๐Ÿ” Torben Hansen