Vulnerability index

Browse CVEs

34 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.6 CVE-2025-65960 Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the con… Contao 4.13.57 / 5.3.42+ Fix from $1,6002025-11-25 MEDIUM 5.3 CVE-2025-57756 Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered … Contao 4.13.56 / 5.3.38+ Fix from $1,6002025-08-28 MEDIUM 5.3 CVE-2025-57757 Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their n… Contao 5.3.38 / 5.6.1+ Fix from $1,6002025-08-28 MEDIUM 5.4 CVE-2025-29790 Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerabi… Contao 4.13.53 / 5.3.30+ Fix from $1,6002025-03-18 MEDIUM 5.4 CVE-2024-45965 Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5… Contao 4.13.54 / 5.3.30+ Fix from $1,6002024-10-02 HIGH 8.8 CVE-2024-45398 Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the… Contao 4.13.49 / 5.3.15+ Fix from $1,9502024-09-17 MEDIUM 5.3 CVE-2024-45612 Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the we… Contao 4.13.49 / 5.3.15+ Fix from $1,6002024-09-17 HIGH 7.1 CVE-2024-30262 Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or t… Contao 4.13.40+ Fix from $1,9502024-04-09 MEDIUM 6.5 CVE-2024-28235 Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links… Contao 4.13.40 / 5.3.4+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-28190 Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code… Contao 4.13.40 / 5.3.4+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-28191 Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert… Contao 4.13.40 / 5.3.4+ Fix from $1,6002024-04-09 MEDIUM 6.1 CVE-2018-5478 Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension. Contao 3.5.32+ Fix from $1,6002023-09-21 MEDIUM 5.4 CVE-2023-36806 Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for u… Contao 4.9.42 / 4.13.28+ Fix from $1,6002023-07-25 MEDIUM 6.5 CVE-2023-29200 Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in … Contao 4.9.40 / 4.13.21+ Fix from $1,6002023-04-25 MEDIUM 6.1 CVE-2022-24899 Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.… Contao after 4.13.2 Fix from $1,6002022-05-06 CRITICAL 9.8 CVE-2022-26265EPSS 30% Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. Contao No fix yet Fix from $2,3002022-03-18 HIGH 7.2 CVE-2021-37626 Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files … Contao 4.4.56 / 4.9.18+ Fix from $1,9502021-08-11 HIGH 7.2 CVE-2021-37627 Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r… Contao 4.4.56 / 4.9.18+ Fix from $1,9502021-08-11 MEDIUM 6.1 CVE-2021-35210 Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table th… Contao 4.9.16 / 4.11.5+ Fix from $1,6002021-06-23 MEDIUM 5.3 CVE-2020-25768 Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end … Contao 4.4.52 / 4.9.6+ Fix from $1,6002020-10-07 MEDIUM 6.1 CVE-2018-10125 Contao before 4.5.7 has XSS in the system log. Contao after 4.5.6 Fix from $1,6002020-03-16 HIGH 8.8 CVE-2012-4383 contao prior to 2.11.4 has a sql injection vulnerability Contao 2.11.4+ Fix from $1,9502020-01-29 CRITICAL 9.8 CVE-2014-1860 Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities Contao Cms after 3.2.4 Fix from $2,3002020-01-08 HIGH 8.8 CVE-2019-19745 Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th… Contao after 4.8.5 Fix from $1,9502019-12-17 MEDIUM 5.3 CVE-2019-19714 Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced… Contao Mitigation only Fix from $1,6002019-12-17 MEDIUM 5.3 CVE-2019-19712 Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been e… Contao after 4.8.5 Fix from $1,6002019-12-17 CRITICAL 9.8 CVE-2019-11512 Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. Contao 4.4.39 / 4.7.5+ Fix from $2,3002019-07-09 CRITICAL 9.8 CVE-2017-16558 Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module. Contao Cms after 4.4.7 Fix from $2,3002019-04-25 CRITICAL 9.8 CVE-2019-10641 Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password. Contao Cms 3.5.39 / 4.7.3+ Fix from $2,3002019-04-17 CRITICAL 9.8 CVE-2019-10643 Contao 4.7 allows Use of a Key Past its Expiration Date. Contao Cms No fix yet Fix from $2,3002019-04-17