CMS
by Contao
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26265 | Cri | 0.66 | 9.8 | 0.30 | Mar 18, 2022 | Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. | ||
| CVE-2014-1860 | Cri | 0.64 | 9.8 | 0.04 | Jan 8, 2020 | Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities | ||
| CVE-2019-19745 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2019 | Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server. | ||
| CVE-2019-11512 | Cri | 0.57 | 9.8 | 0.01 | Jul 9, 2019 | Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. | ||
| CVE-2017-16558 | Cri | 0.57 | 9.8 | 0.01 | Apr 25, 2019 | Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module. | ||
| CVE-2019-10643 | Cri | 0.57 | 9.8 | 0.01 | Apr 17, 2019 | Contao 4.7 allows Use of a Key Past its Expiration Date. | ||
| CVE-2019-10641 | Cri | 0.57 | 9.8 | 0.01 | Apr 17, 2019 | Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password. | ||
| CVE-2017-10993 | Hig | 0.57 | 8.8 | 0.02 | Jul 21, 2017 | Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal. | ||
| CVE-2021-37627 | Hig | 0.52 | 8.0 | 0.01 | Aug 11, 2021 | Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form… | ||
| CVE-2012-4383 | Hig | 0.50 | 8.8 | 0.01 | Jan 29, 2020 | contao prior to 2.11.4 has a sql injection vulnerability | ||
| CVE-2019-10642 | Hig | 0.50 | 8.8 | 0.01 | Apr 17, 2019 | Contao 4.7 allows CSRF. | ||
| CVE-2024-45398 | Hig | 0.47 | 8.3 | 0.01 | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web… | ||
| CVE-2024-28235 | Hig | 0.47 | 8.3 | 0.01 | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for… | ||
| CVE-2021-37626 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2021 | Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the… | ||
| CVE-2022-24899 | Hig | 0.40 | 7.2 | 0.04 | May 6, 2022 | Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page… | ||
| CVE-2021-35210 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end. | ||
| CVE-2018-10125 | Med | 0.40 | 6.1 | 0.01 | Mar 16, 2020 | Contao before 4.5.7 has XSS in the system log. | ||
| CVE-2025-65960 | Med | 0.36 | 6.6 | 0.00 | Nov 25, 2025 | Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched… | ||
| CVE-2025-29790 | Med | 0.35 | 5.4 | 0.00 | Mar 18, 2025 | Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6. | ||
| CVE-2024-45965 | Med | 0.35 | 6.4 | 0.00 | Oct 2, 2024 | Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6. |
- risk 0.66cvss 9.8epss 0.30
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
- risk 0.64cvss 9.8epss 0.04
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
- risk 0.57cvss 8.8epss 0.01
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
- risk 0.57cvss 9.8epss 0.01
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
- risk 0.57cvss 9.8epss 0.01
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
- risk 0.57cvss 9.8epss 0.01
Contao 4.7 allows Use of a Key Past its Expiration Date.
- risk 0.57cvss 9.8epss 0.01
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
- risk 0.57cvss 8.8epss 0.02
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
- risk 0.52cvss 8.0epss 0.01
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form…
- risk 0.50cvss 8.8epss 0.01
contao prior to 2.11.4 has a sql injection vulnerability
- risk 0.50cvss 8.8epss 0.01
Contao 4.7 allows CSRF.
- risk 0.47cvss 8.3epss 0.01
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web…
- risk 0.47cvss 8.3epss 0.01
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for…
- risk 0.47cvss 7.2epss 0.01
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the…
- risk 0.40cvss 7.2epss 0.04
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page…
- risk 0.40cvss 6.1epss 0.01
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
- risk 0.40cvss 6.1epss 0.01
Contao before 4.5.7 has XSS in the system log.
- risk 0.36cvss 6.6epss 0.00
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched…
- risk 0.35cvss 5.4epss 0.00
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
- risk 0.35cvss 6.4epss 0.00
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.
Page 1 of 3