๐Ÿ” CVE Alert

CVE-2026-77137

UNKNOWN 0.0

SQL Injection in extension "Forms Export" (frp_form_answers)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and read access to the "Forms Export" Backend module.

CWE CWE-89
Vendor typo3
Product extension "forms export"
Published Aug 25, 2026
Last Updated Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 extension "forms export"

Be the first to know when new unknown vulnerabilities affecting typo3 extension "forms export" are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / Extension "Forms Export"
7.0.0 < 7.1.1 6.0.0 < 6.1.3 0 < 5.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-ext-sa-2026-027

Credits

Dijar Bytyci