CVE-2026-8726 Details
Description
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
A SQL injection vulnerability has been identified in the TYPO3 extension 'News system' (news), specifically in versions 14.0.0 to 14.0.2, 13.0.0 to 13.0.1, 12.0.0 to 12.3.1, and 11.4.3 and below. The vulnerability arises because the extension does not properly sanitize user input before incorporating it into database queries. This flaw allows an unauthenticated attacker to inject arbitrary SQL through a URL parameter on pages that utilize the 'Date Menu of news articles' plugin. Exploitation requires the 'Date Menu of news articles' plugin to be active and the TypoScript/Plugin setting 'disableOverrideDemand' to be disabled.
Users are advised to update to version 14.0.3, 13.0.2, 12.3.2, or 11.4.4. The updated versions are available through the TYPO3 extension manager, Packagist, and from the TYPO3 Extensions Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-010 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 News system | >= 11.4.0, <= 11.4.3 (semver) >= 12.0.0, <= 12.3.1 (semver) >= 13.0.0, <= 13.0.1 (semver) >= 14.0.0, <= 14.0.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | TYPO3 |
Volerion