{"id":"CVE-2026-8726","aliases":["GHSA-g868-j3qm-4j28"],"url":"https://o3.security/vulnerability/CVE-2026-8726","summary":"SQL Injection in extension \"News system\" (news)","details":"The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the \"Date Menu of news articles\" plugin. Exploitation requires the \"Date Menu of news articles\" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.","published":"2026-05-19T09:22:09.037Z","modified":"2026-08-12T03:51:37.357546418Z","cvss":null,"epss":{"score":0.00386,"percentile":0.31829,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"georgringer/news","fixedVersion":"12.3.2"},{"ecosystem":"Packagist","name":"georgringer/news","fixedVersion":"13.0.2"},{"ecosystem":"Packagist","name":"georgringer/news","fixedVersion":"14.0.3"},{"ecosystem":"Packagist","name":"georgringer/news","fixedVersion":"10.0.4"},{"ecosystem":"Packagist","name":"georgringer/news","fixedVersion":"11.4.4"}],"fix":null,"references":[{"type":"WEB","url":"https://packagist.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8726.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8726"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-010"},{"type":"PACKAGE","url":"https://github.com/georgringer/news"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.357546418Z"}}