VYPR
Medium severity5.3NVD Advisory· Published Aug 28, 2025· Updated Jun 17, 2026

CVE-2025-57757

CVE-2025-57757

Description

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
contao/core-bundlePackagist
>= 5.0.0-RC1, < 5.3.385.3.38
contao/core-bundlePackagist
>= 5.4.0-RC1, < 5.6.15.6.1
contao/contaoPackagist
>= 5.0.0-RC1, < 5.3.385.3.38
contao/contaoPackagist
>= 5.4.0-RC1, < 5.6.15.6.1

Affected products

4
  • Contao/CMScpe-rescue2 versions
    >= 5.0.0-RC1, < 5.3.38+ 1 more
    • (no CPE)range: >= 5.0.0-RC1, < 5.3.38
    • cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*range: >=5.3.0,<5.3.38
  • ghsa-coords2 versions
    >= 5.0.0-RC1, < 5.3.38+ 1 more
    • (no CPE)range: >= 5.0.0-RC1, < 5.3.38
    • (no CPE)range: >= 5.0.0-RC1, < 5.3.38

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.