VYPR

CMS

by Contao

CVEs (46)

  • CVE-2022-26265CriMar 18, 2022
    risk 0.66cvss 9.8epss 0.30

    Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

  • CVE-2014-1860CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.04

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

  • CVE-2019-19745HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.

  • CVE-2019-11512CriJul 9, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.

  • CVE-2017-16558CriApr 25, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

  • CVE-2019-10643CriApr 17, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao 4.7 allows Use of a Key Past its Expiration Date.

  • CVE-2019-10641CriApr 17, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

  • CVE-2017-10993HigJul 21, 2017
    risk 0.57cvss 8.8epss 0.02

    Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.

  • CVE-2021-37627HigAug 11, 2021
    risk 0.52cvss 8.0epss 0.01

    Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form…

  • CVE-2012-4383HigJan 29, 2020
    risk 0.50cvss 8.8epss 0.01

    contao prior to 2.11.4 has a sql injection vulnerability

  • CVE-2019-10642HigApr 17, 2019
    risk 0.50cvss 8.8epss 0.01

    Contao 4.7 allows CSRF.

  • CVE-2024-45398HigSep 17, 2024
    risk 0.47cvss 8.3epss 0.01

    Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web…

  • CVE-2024-28235HigApr 9, 2024
    risk 0.47cvss 8.3epss 0.01

    Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for…

  • CVE-2021-37626HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the…

  • CVE-2022-24899HigMay 6, 2022
    risk 0.40cvss 7.2epss 0.04

    Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page…

  • CVE-2021-35210MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.

  • CVE-2018-10125MedMar 16, 2020
    risk 0.40cvss 6.1epss 0.01

    Contao before 4.5.7 has XSS in the system log.

  • CVE-2025-65960MedNov 25, 2025
    risk 0.36cvss 6.6epss 0.00

    Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched…

  • CVE-2025-29790MedMar 18, 2025
    risk 0.35cvss 5.4epss 0.00

    Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.

  • CVE-2024-45965MedOct 2, 2024
    risk 0.35cvss 6.4epss 0.00

    Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

Page 1 of 3