Skip to main navigation Skip to main content Skip to page footer

Vulnerabilities in multiple third party TYPO3 CMS extensions

25 August 2026 ยท TYPO3 Security Team
Dear TYPO3 users,

several vulnerabilities have been found in the following third party TYPO3
extensions:

- "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
- "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
- "Modules" (modules)
- "Mask" (mask)
- "Telephone Directory" (telephonedirectory)
- "Club Directory" (clubdirectory)
- "Industry Directory" (yellowpages2)
- "Forum" (pforum)
- "powermail" (powermail)
- "Event management and registration" (sf_event_mgt)
- "femanager" (femanager)
- "Apache Solr for TYPO3 - Enterprise Search" (solr)
- "Events 2" (events2)
- "Forms Export" (frp_form_answers)

For further information on the issues, please read the related advisories
TYPO3-EXT-SA-2026-014, TYPO3-EXT-SA-2026-015, TYPO3-EXT-SA-2026-016,
TYPO3-EXT-SA-2026-017, TYPO3-EXT-SA-2026-018, TYPO3-EXT-SA-2026-019,
TYPO3-EXT-SA-2026-020, TYPO3-EXT-SA-2026-021, TYPO3-EXT-SA-2026-022,
TYPO3-EXT-SA-2026-023, TYPO3-EXT-SA-2026-024, TYPO3-EXT-SA-2026-025,
TYPO3-EXT-SA-2026-026 and TYPO3-EXT-SA-2026-027 which were published today:

TYPO3-EXT-SA-2026-014: Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-014

TYPO3-EXT-SA-2026-015: Multiple Vulnerabilities in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-015

TYPO3-EXT-SA-2026-016: Information Disclosure in extension "Modules" (modules)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-016

TYPO3-EXT-SA-2026-017: Path Traversal in extension "Mask" (mask)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-017

TYPO3-EXT-SA-2026-018: Broken Access Control in extension "Telephone Directory" (telephonedirectory)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-018

TYPO3-EXT-SA-2026-019: Broken Access Control in extension "Club Directory" (clubdirectory)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-019

TYPO3-EXT-SA-2026-020: Broken Access Control in extension "Industry Directory" (yellowpages2)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-020

TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021

TYPO3-EXT-SA-2026-022: Server-Side Template Injection (SSTI) in extension "powermail" (powermail)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-022

TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023

TYPO3-EXT-SA-2026-024: Multiple vulnerabilities in extension "femanager" (femanager)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-024

TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025

TYPO3-EXT-SA-2026-026: Broken Access Control in extension "Events 2" (events2)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-026

TYPO3-EXT-SA-2026-027: SQL Injection in extension "Forms Export" (frp_form_answers)
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-027

In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Guide: 
https://docs.typo3.org/typo3cms/CoreApiReference/Security/Index.html

See all TYPO3 security advisories: 
https://news.typo3.com/security

Best regards,

Torben Hansen
Member of the TYPO3 Security Team