Filtered by vendor Typo3 Subscriptions
Filtered by product Extension "html5 Video Player Vs. Powermail" Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-77138 1 Typo3 1 Extension "html5 Video Player Vs. Powermail" 2026-08-28 N/A
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.