Typo3 · Extension "Forms Export" · CVE-2026-77137
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
The extension fails to properly sanitize user input before using it in a database query. This allows a low-privileged backend user with read access to the "Forms Export" backend module to perform SQL injection, which is a technique used to execute arbitrary database commands, through a URL parameter.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.