VYPR

Forms Export

by TYPO3

CVEs (2)

  • CVE-2026-77137HigAug 25, 2026
    risk 0.50cvss —epss 0.00

    The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and…

  • CVE-2023-26091MedFeb 26, 2023
    risk 0.33cvss 6.1epss 0.00

    The frp_form_answers (aka Forms Export) extension before 3.1.2, and 4.x before 4.0.2, for TYPO3 allows XSS via saved emails.