CVE-2024-45612
- EPSS 0.55%
- Veröffentlicht 17.09.2024 19:15:28
- Zuletzt bearbeitet 23.09.2024 19:33:04
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to u...
CVE-2024-30262
- EPSS 0.28%
- Veröffentlicht 09.04.2024 17:16:02
- Zuletzt bearbeitet 09.01.2025 17:51:27
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises...
CVE-2024-28235
- EPSS 0.41%
- Veröffentlicht 09.04.2024 16:15:07
- Zuletzt bearbeitet 17.01.2025 15:42:02
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for...
CVE-2024-28190
- EPSS 1.4%
- Veröffentlicht 09.04.2024 14:15:08
- Zuletzt bearbeitet 16.01.2025 19:54:16
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and p...
CVE-2024-28234
- EPSS 0.7%
- Veröffentlicht 09.04.2024 14:15:08
- Zuletzt bearbeitet 02.01.2025 17:49:55
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4...
CVE-2024-28191
- EPSS 0.96%
- Veröffentlicht 09.04.2024 14:15:08
- Zuletzt bearbeitet 17.01.2025 15:39:22
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 a...
CVE-2018-5478
- EPSS 0.08%
- Veröffentlicht 21.09.2023 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:08:52
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
CVE-2023-36806
- EPSS 0.19%
- Veröffentlicht 25.07.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:10:38
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be e...
CVE-2023-29200
- EPSS 0.49%
- Veröffentlicht 25.04.2023 18:15:09
- Zuletzt bearbeitet 02.01.2025 17:22:06
Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents o...
CVE-2022-24899
- EPSS 53.53%
- Veröffentlicht 06.05.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:21
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonica...