Filtered by vendor Typo3 Subscriptions
Filtered by product Extension "forms Export" Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-77137 1 Typo3 1 Extension "forms Export" 2026-08-28 N/A
The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and read access to the "Forms Export" Backend module.