CVE-2025-65961
- EPSS 0.03%
- Veröffentlicht 25.11.2025 19:15:51
- Zuletzt bearbeitet 03.12.2025 18:20:37
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patche...
CVE-2025-65960
- EPSS 0.02%
- Veröffentlicht 25.11.2025 18:54:48
- Zuletzt bearbeitet 03.12.2025 17:55:34
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. ...
CVE-2025-57759
- EPSS 0.04%
- Veröffentlicht 28.08.2025 16:32:59
- Zuletzt bearbeitet 02.09.2025 17:36:12
Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patch...
CVE-2025-57758
- EPSS 0.04%
- Veröffentlicht 28.08.2025 16:32:38
- Zuletzt bearbeitet 02.09.2025 17:37:58
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 ...
CVE-2025-57757
- EPSS 0.04%
- Veröffentlicht 28.08.2025 16:32:03
- Zuletzt bearbeitet 02.09.2025 17:38:34
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched...
CVE-2025-57756
- EPSS 0.04%
- Veröffentlicht 28.08.2025 16:31:40
- Zuletzt bearbeitet 02.09.2025 17:39:29
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been p...
CVE-2025-29790
- EPSS 0.14%
- Veröffentlicht 18.03.2025 18:36:34
- Zuletzt bearbeitet 04.11.2025 18:22:48
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
CVE-2024-45965
- EPSS 0.45%
- Veröffentlicht 02.10.2024 20:15:11
- Zuletzt bearbeitet 13.11.2025 14:50:19
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.
CVE-2024-45604
- EPSS 0.75%
- Veröffentlicht 17.09.2024 20:15:04
- Zuletzt bearbeitet 25.09.2024 19:22:09
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulner...
CVE-2024-45398
- EPSS 0.21%
- Veröffentlicht 17.09.2024 20:15:04
- Zuletzt bearbeitet 25.09.2024 19:20:52
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are a...