CVE-2026-8827: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in TYPO3 Extension "Address List"
CVE-2026-8827 is a high-severity SQL Injection vulnerability in the TYPO3 Extension "Address List". The vulnerability arises because the AddressRepository::getSqlQuery() method constructs SQL queries without properly sanitizing user input. However, this method is not called anywhere within the extension by default, so the vulnerability does not pose a direct risk in a default installation. The risk exists if custom extensions invoke this method with untrusted input, potentially exposing the site to SQL injection attacks.
AI Analysis
Technical Summary
The TYPO3 Extension "Address List" contains a SQL Injection vulnerability (CWE-89) in the AddressRepository::getSqlQuery() method due to improper neutralization of special elements in SQL commands. Although the vulnerable method is present, it is not invoked internally by the extension itself, meaning the default installation is not directly exploitable. Custom extensions that call this method with unsanitized, untrusted input could trigger SQL injection, allowing an attacker to manipulate database queries. The vulnerability affects specific versions including 0, 9.0.0, and 10.0.0 of the extension. No official patch or remediation level has been published yet.
Potential Impact
If exploited via a custom extension that calls the vulnerable method with untrusted input, an attacker could perform SQL injection attacks, potentially leading to unauthorized data access or manipulation. Since the vulnerable method is not used by the extension itself, default installations are not directly impacted. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerable method is not called in the default extension, no immediate action is required for default installations. Developers creating custom extensions should avoid calling AddressRepository::getSqlQuery() with untrusted input or implement proper input sanitization to prevent SQL injection.
CVE-2026-8827: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in TYPO3 Extension "Address List"
Description
CVE-2026-8827 is a high-severity SQL Injection vulnerability in the TYPO3 Extension "Address List". The vulnerability arises because the AddressRepository::getSqlQuery() method constructs SQL queries without properly sanitizing user input. However, this method is not called anywhere within the extension by default, so the vulnerability does not pose a direct risk in a default installation. The risk exists if custom extensions invoke this method with untrusted input, potentially exposing the site to SQL injection attacks.
CVSS v4.0
Score 8.2high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The TYPO3 Extension "Address List" contains a SQL Injection vulnerability (CWE-89) in the AddressRepository::getSqlQuery() method due to improper neutralization of special elements in SQL commands. Although the vulnerable method is present, it is not invoked internally by the extension itself, meaning the default installation is not directly exploitable. Custom extensions that call this method with unsanitized, untrusted input could trigger SQL injection, allowing an attacker to manipulate database queries. The vulnerability affects specific versions including 0, 9.0.0, and 10.0.0 of the extension. No official patch or remediation level has been published yet.
Potential Impact
If exploited via a custom extension that calls the vulnerable method with untrusted input, an attacker could perform SQL injection attacks, potentially leading to unauthorized data access or manipulation. Since the vulnerable method is not used by the extension itself, default installations are not directly impacted. No known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerable method is not called in the default extension, no immediate action is required for default installations. Developers creating custom extensions should avoid calling AddressRepository::getSqlQuery() with untrusted input or implement proper input sanitization to prevent SQL injection.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TYPO3
- Date Reserved
- 2026-05-18T11:19:55.225Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a0c3637ec166c07b08eb1c3
Added to database: 05/19/2026, 10:06:47 UTC
Last enriched: 06/29/2026, 22:16:03 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.