CVE-2026-55824
- EPSS 0.15%
- Veröffentlicht 31.07.2026 19:17:11
- Zuletzt bearbeitet 31.07.2026 20:16:52
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains...
CVE-2026-55825
- EPSS 0.21%
- Veröffentlicht 31.07.2026 19:07:40
- Zuletzt bearbeitet 01.08.2026 00:17:17
Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file from another jo...
CVE-2026-57232
- EPSS 0.18%
- Veröffentlicht 31.07.2026 18:29:53
- Zuletzt bearbeitet 03.08.2026 18:16:39
Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or private-address v...
CVE-2025-65961
- EPSS 0.16%
- Veröffentlicht 25.11.2025 19:15:51
- Zuletzt bearbeitet 03.12.2025 18:20:37
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patche...
CVE-2025-65960
- EPSS 0.17%
- Veröffentlicht 25.11.2025 18:54:48
- Zuletzt bearbeitet 03.12.2025 17:55:34
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. ...
CVE-2025-57759
- EPSS 0.24%
- Veröffentlicht 28.08.2025 16:32:59
- Zuletzt bearbeitet 02.09.2025 17:36:12
Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patch...
CVE-2025-57758
- EPSS 0.24%
- Veröffentlicht 28.08.2025 16:32:38
- Zuletzt bearbeitet 02.09.2025 17:37:58
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 ...
CVE-2025-57757
- EPSS 0.3%
- Veröffentlicht 28.08.2025 16:32:03
- Zuletzt bearbeitet 02.09.2025 17:38:34
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched...
CVE-2025-57756
- EPSS 0.29%
- Veröffentlicht 28.08.2025 16:31:40
- Zuletzt bearbeitet 02.09.2025 17:39:29
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been p...
CVE-2025-29790
- EPSS 0.22%
- Veröffentlicht 18.03.2025 18:36:34
- Zuletzt bearbeitet 04.11.2025 18:22:48
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.