SQL Injection Vulnerability in TYPO3's Forms Export Module
CVE-2026-77137

7.7HIGH

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77137?

The TYPO3 Forms Export module is vulnerable due to inadequate sanitization of user input, enabling low-privileged backend users to conduct SQL injection attacks via a URL parameter. This security flaw permits attackers to manipulate database queries if they possess read access to the Forms Export backend module. Proper input validation measures are essential to mitigate such vulnerabilities and protect the integrity of the database.

Affected Version(s)

Extension "Forms Export" 7.0.0 < 7.1.1

Extension "Forms Export" 6.0.0 < 6.1.3

Extension "Forms Export" 0 < 5.0.5

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dijar Bytyci
.