{"id":"GHSA-g868-j3qm-4j28","summary":"georgringer/news has SQL Injection in extension \"News system\" (news)","details":"The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the \"Date Menu of news articles\" plugin. Exploitation requires the \"Date Menu of news articles\" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.","aliases":["CVE-2026-8726"],"modified":"2026-09-10T03:51:05.548810812Z","published":"2026-05-19T12:31:39Z","database_specific":{"github_reviewed_at":"2026-06-08T17:52:51Z","nvd_published_at":"2026-05-19T10:16:25Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8726"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/georgringer/news/CVE-2026-8726.yaml"},{"type":"PACKAGE","url":"https://github.com/georgringer/news"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-010"}],"affected":[{"package":{"name":"georgringer/news","ecosystem":"Packagist","purl":"pkg:composer/georgringer/news"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.0.0"},{"fixed":"12.3.2"}]}],"versions":["12.0.0","12.1.0","12.2.0","12.3.0","12.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g868-j3qm-4j28/GHSA-g868-j3qm-4j28.json"}},{"package":{"name":"georgringer/news","ecosystem":"Packagist","purl":"pkg:composer/georgringer/news"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.0.0"},{"fixed":"13.0.2"}]}],"versions":["13.0.0","13.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g868-j3qm-4j28/GHSA-g868-j3qm-4j28.json"}},{"package":{"name":"georgringer/news","ecosystem":"Packagist","purl":"pkg:composer/georgringer/news"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"14.0.3"}]}],"versions":["14.0.0","14.0.1","14.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g868-j3qm-4j28/GHSA-g868-j3qm-4j28.json"}},{"package":{"name":"georgringer/news","ecosystem":"Packagist","purl":"pkg:composer/georgringer/news"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3","3.1.0","3.2.0","3.2.1","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.9","4.0.0","4.1.0","4.2.0","4.2.1","4.3.0","4.3.1","4.3.2","5.0.0","5.1.0","5.2.0","5.3.0","5.3.1","5.3.2","5.3.3","6.0.0","6.1.0","6.1.1","6.2.0","6.2.1","6.3.0","7.0.0","7.0.1","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.1.0","7.2.0","7.2.1","7.2.2","7.2.3","7.3.0","7.3.1","8.0.0","8.1.0","8.1.1","8.2.0","8.3.0","8.4.0","8.4.1","8.5.0","8.5.1","8.5.2","8.6.0","9.0.0","9.1.0","9.1.1","9.2.0","9.3.0","9.3.1","9.4.0","9.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g868-j3qm-4j28/GHSA-g868-j3qm-4j28.json"}},{"package":{"name":"georgringer/news","ecosystem":"Packagist","purl":"pkg:composer/georgringer/news"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"fixed":"11.4.4"}]}],"versions":["11.0.0","11.1.0","11.1.1","11.1.2","11.2.0","11.3.0","11.4.0","11.4.1","11.4.2","11.4.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-g868-j3qm-4j28/GHSA-g868-j3qm-4j28.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}