CVE-2026-77138
TYPO3 Extension "HTML5 Video Player vs. Powermail"
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.
- CVSS
- 9.3
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.25