Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.6
CVE-2025-65960
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the con…
Contao
4.13.57 / 5.3.42+
MEDIUM 5.3
CVE-2025-57756
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered …
Contao
4.13.56 / 5.3.38+
MEDIUM 5.3
CVE-2025-57757
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their n…
Contao
5.3.38 / 5.6.1+
MEDIUM 5.4
CVE-2025-29790
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerabi…
Contao
4.13.53 / 5.3.30+
MEDIUM 5.4
CVE-2024-45965
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5…
Contao
4.13.54 / 5.3.30+
HIGH 8.8
CVE-2024-45398
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the…
Contao
4.13.49 / 5.3.15+
MEDIUM 5.3
CVE-2024-45612
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the we…
Contao
4.13.49 / 5.3.15+
HIGH 7.1
CVE-2024-30262
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or t…
Contao
4.13.40+
MEDIUM 6.5
CVE-2024-28235
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links…
Contao
4.13.40 / 5.3.4+
MEDIUM 5.4
CVE-2024-28190
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code…
Contao
4.13.40 / 5.3.4+
MEDIUM 5.4
CVE-2024-28191
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert…
Contao
4.13.40 / 5.3.4+
MEDIUM 6.1
CVE-2018-5478
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
Contao
3.5.32+
MEDIUM 5.4
CVE-2023-36806
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for u…
Contao
4.9.42 / 4.13.28+
MEDIUM 6.5
CVE-2023-29200
Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in …
Contao
4.9.40 / 4.13.21+
MEDIUM 6.1
CVE-2022-24899
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.…
Contao
after 4.13.2
CRITICAL 9.8
CVE-2022-26265EPSS 30%
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
Contao
No fix yet
HIGH 7.2
CVE-2021-37626
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …
Contao
4.4.56 / 4.9.18+
HIGH 7.2
CVE-2021-37627
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r…
Contao
4.4.56 / 4.9.18+
MEDIUM 6.1
CVE-2021-35210
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table th…
Contao
4.9.16 / 4.11.5+
MEDIUM 5.3
CVE-2020-25768
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end …
Contao
4.4.52 / 4.9.6+
MEDIUM 6.1
CVE-2018-10125
Contao before 4.5.7 has XSS in the system log.
Contao
after 4.5.6
HIGH 8.8
CVE-2012-4383
contao prior to 2.11.4 has a sql injection vulnerability
Contao
2.11.4+
CRITICAL 9.8
CVE-2014-1860
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
Contao Cms
after 3.2.4
HIGH 8.8
CVE-2019-19745
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th…
Contao
after 4.8.5
MEDIUM 5.3
CVE-2019-19714
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced…
Contao
Mitigation only
MEDIUM 5.3
CVE-2019-19712
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been e…
Contao
after 4.8.5
CRITICAL 9.8
CVE-2019-11512
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
Contao
4.4.39 / 4.7.5+
CRITICAL 9.8
CVE-2017-16558
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
Contao Cms
after 4.4.7
CRITICAL 9.8
CVE-2019-10641
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Contao Cms
3.5.39 / 4.7.3+
CRITICAL 9.8
CVE-2019-10643
Contao 4.7 allows Use of a Key Past its Expiration Date.
Contao Cms
No fix yet