Dear TYPO3 users,
several vulnerabilities have been found in the following third party TYPO3
extensions:
- "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
- "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
- "Modules" (modules)
- "Mask" (mask)
- "Telephone Directory" (telephonedirectory)
- "Club Directory" (clubdirectory)
- "Industry Directory" (yellowpages2)
- "Forum" (pforum)
- "powermail" (powermail)
- "Event management and registration" (sf_event_mgt)
- "femanager" (femanager)
- "Apache Solr for TYPO3 - Enterprise Search" (solr)
- "Events 2" (events2)
- "Forms Export" (frp_form_answers)
For further information on the issues, please read the related advisories
TYPO3-EXT-SA-2026-014, TYPO3-EXT-SA-2026-015, TYPO3-EXT-SA-2026-016,
TYPO3-EXT-SA-2026-017, TYPO3-EXT-SA-2026-018, TYPO3-EXT-SA-2026-019,
TYPO3-EXT-SA-2026-020, TYPO3-EXT-SA-2026-021, TYPO3-EXT-SA-2026-022,
TYPO3-EXT-SA-2026-023, TYPO3-EXT-SA-2026-024, TYPO3-EXT-SA-2026-025,
TYPO3-EXT-SA-2026-026 and TYPO3-EXT-SA-2026-027 which were published today:
TYPO3-EXT-SA-2026-014: Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-014
TYPO3-EXT-SA-2026-015: Multiple Vulnerabilities in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-015
TYPO3-EXT-SA-2026-016: Information Disclosure in extension "Modules" (modules)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-016
TYPO3-EXT-SA-2026-017: Path Traversal in extension "Mask" (mask)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-017
TYPO3-EXT-SA-2026-018: Broken Access Control in extension "Telephone Directory" (telephonedirectory)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-018
TYPO3-EXT-SA-2026-019: Broken Access Control in extension "Club Directory" (clubdirectory)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-019
TYPO3-EXT-SA-2026-020: Broken Access Control in extension "Industry Directory" (yellowpages2)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-020
TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021
TYPO3-EXT-SA-2026-022: Server-Side Template Injection (SSTI) in extension "powermail" (powermail)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-022
TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023
TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-024
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025
TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-026
TYPO3-EXT-SA-2026-027: SQL Injection in extension "Forms Export" (frp_form_answers)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-027
In general the TYPO3 Security Team recommends to read the following pages:
The TYPO3 Security Guide:
https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html
See all TYPO3 security advisories:
https://news.typo3.com/security
Best regards,
Torben Hansen
Member of the TYPO3 Security Team