Vulnerability index

Browse CVEs

34 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Contao MEDIUM 6.6
CVE-2025-65960

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the con…

Fix: 4.13.57 / 5.3.42+
Fix from $1,600 2025-11-25
Contao MEDIUM 5.3
CVE-2025-57756

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered …

Fix: 4.13.56 / 5.3.38+
Fix from $1,600 2025-08-28
Contao MEDIUM 5.3
CVE-2025-57757

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their n…

Fix: 5.3.38 / 5.6.1+
Fix from $1,600 2025-08-28
Contao MEDIUM 5.4
CVE-2025-29790

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerabi…

Fix: 4.13.53 / 5.3.30+
Fix from $1,600 2025-03-18
Contao MEDIUM 5.4
CVE-2024-45965

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5…

Fix: 4.13.54 / 5.3.30+
Fix from $1,600 2024-10-02
Contao HIGH 8.8
CVE-2024-45398

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the…

Fix: 4.13.49 / 5.3.15+
Fix from $1,950 2024-09-17
Contao MEDIUM 5.3
CVE-2024-45612

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the we…

Fix: 4.13.49 / 5.3.15+
Fix from $1,600 2024-09-17
Contao HIGH 7.1
CVE-2024-30262

Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or t…

Fix: 4.13.40+
Fix from $1,950 2024-04-09
Contao MEDIUM 6.5
CVE-2024-28235

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links…

Fix: 4.13.40 / 5.3.4+
Fix from $1,600 2024-04-09
Contao MEDIUM 5.4
CVE-2024-28190

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code…

Fix: 4.13.40 / 5.3.4+
Fix from $1,600 2024-04-09
Contao MEDIUM 5.4
CVE-2024-28191

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert…

Fix: 4.13.40 / 5.3.4+
Fix from $1,600 2024-04-09
Contao MEDIUM 6.1
CVE-2018-5478

Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.

Fix: 3.5.32+
Fix from $1,600 2023-09-21
Contao MEDIUM 5.4
CVE-2023-36806

Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for u…

Fix: 4.9.42 / 4.13.28+
Fix from $1,600 2023-07-25
Contao MEDIUM 6.5
CVE-2023-29200

Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in …

Fix: 4.9.40 / 4.13.21+
Fix from $1,600 2023-04-25
Contao MEDIUM 6.1
CVE-2022-24899

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.…

Fix: after 4.13.2
Fix from $1,600 2022-05-06
Contao CRITICAL 9.8
CVE-2022-26265EPSS 30%

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

No fix yet
Fix from $2,300 2022-03-18
Contao HIGH 7.2
CVE-2021-37626

Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …

Fix: 4.4.56 / 4.9.18+
Fix from $1,950 2021-08-11
Contao HIGH 7.2
CVE-2021-37627

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r…

Fix: 4.4.56 / 4.9.18+
Fix from $1,950 2021-08-11
Contao MEDIUM 6.1
CVE-2021-35210

Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table th…

Fix: 4.9.16 / 4.11.5+
Fix from $1,600 2021-06-23
Contao MEDIUM 5.3
CVE-2020-25768

Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end …

Fix: 4.4.52 / 4.9.6+
Fix from $1,600 2020-10-07
Contao MEDIUM 6.1
CVE-2018-10125

Contao before 4.5.7 has XSS in the system log.

Fix: after 4.5.6
Fix from $1,600 2020-03-16
Contao HIGH 8.8
CVE-2012-4383

contao prior to 2.11.4 has a sql injection vulnerability

Fix: 2.11.4+
Fix from $1,950 2020-01-29
Contao Cms CRITICAL 9.8
CVE-2014-1860

Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

Fix: after 3.2.4
Fix from $2,300 2020-01-08
Contao HIGH 8.8
CVE-2019-19745

Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th…

Fix: after 4.8.5
Fix from $1,950 2019-12-17
Contao MEDIUM 5.3
CVE-2019-19714

Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced…

Mitigation only
Fix from $1,600 2019-12-17
Contao MEDIUM 5.3
CVE-2019-19712

Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been e…

Fix: after 4.8.5
Fix from $1,600 2019-12-17
Contao CRITICAL 9.8
CVE-2019-11512

Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.

Fix: 4.4.39 / 4.7.5+
Fix from $2,300 2019-07-09
Contao Cms CRITICAL 9.8
CVE-2017-16558

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

Fix: after 4.4.7
Fix from $2,300 2019-04-25
Contao Cms CRITICAL 9.8
CVE-2019-10641

Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

Fix: 3.5.39 / 4.7.3+
Fix from $2,300 2019-04-17
Contao Cms CRITICAL 9.8
CVE-2019-10643

Contao 4.7 allows Use of a Key Past its Expiration Date.

No fix yet
Fix from $2,300 2019-04-17