Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-77138: HTML5 Video Player vs. Powermail lets attackers run code on TYPO3
CVE-2026-77138 · published 1 month ago
Summary
The HTML5 Video Player vs. Powermail add‑on for TYPO3 does not properly check data it receives from a user’s web browser. A malicious user can send a specially crafted cookie that tricks the system into executing code on the server. Update the extension to the latest version or remove it if it is no longer needed, and make sure your TYPO3 installation receives regular security updates.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| typo3 | extension "html5 video player vs. powermail" | <= 0.2.1 |
Original advisory text
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published25 Aug 2026
Updated7 Oct 2026
First seen25 Aug 2026
Track software like this
Free during beta