I just ran the zap test again and we didn't receive the emails this time although there are some errors which I believe I have to address with the service provider regarding the ability to do "directory browsing".
The scan still doesn't like the registration and contact-us pages simply because you can write to the database and they were able to bypass the validation. I would think that this is a risk anyone takes if the allow people to register to your site though.
Thanks for your help. Hope we are in the clear now.