CVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
| CWE | CWE-502 |
| Vendor | typo3 |
| Product | extension "html5 video player vs. powermail" |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 extension "html5 video player vs. powermail"
Be the first to know when new unknown vulnerabilities affecting typo3 extension "html5 video player vs. powermail" are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TYPO3 / Extension "HTML5 Video Player vs. Powermail"
0 โค 0.2.1
References
Credits
๐ Torben Hansen