CVE-2026-77136 | TYPO3 Powermail up to 10.9.2/12.6.0/13.2.0 Fluid View sender_name code injection
A vulnerability was found in TYPO3 Powermail up to 10.9.2/12.6.0/13.2.0 and classified as critical. The affected element is an unknown function of the component Fluid View. Executing a manipulation of the argument sender_name can lead to code injection.
This vulnerability is tracked as CVE-2026-77136. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More