CVE-2026-8827HIGHCVSS 0.0

TYPO3 SQL Injection in extension "Address List" (tt_address)

Published May 19, 2026·Updated Jun 29, 2026

Description

In the TYPO3 extension `tt_address`, the `AddressRepository::getSqlQuery()` method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call this method with untrusted input would expose the site to SQL injection. This has been patched in version 8.1.2, 9.1.1, and 10.0.1.

Affected Packages (1)

friendsoftypo3/tt-addressCOMPOSER
From 10.0.0
Fixed in 10.0.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free