CVE-2023-41100: Hcaptcha For Ext:form Project Hcaptcha For Ext:form

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in the hcaptcha (aka hCaptcha for EXT:form) extension before 2.1.2 for TYPO3. It fails to check that the required captcha field is submitted in the form data. allowing a remote user to bypass the CAPTCHA check.

Affected products

Published 2023-08-23. Last modified 2026-06-17.