Improper Neutralization of Special Elements Used in a Template Engine in Event management and registration - CVE-2026-77129
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A remote user can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects.