CVE-2026-77137
SQL Injection in extension "Forms Export" (frp_form_answers)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and read access to the "Forms Export" Backend module.
| Vendor | typo3 |
| Product | extension "forms export" |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 extension "forms export"
Be the first to know when new unknown vulnerabilities affecting typo3 extension "forms export" are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup