CVE-2024-45965
- EPSS 0.32%
- Veröffentlicht 02.10.2024 20:15:11
- Zuletzt bearbeitet 13.11.2025 14:50:19
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.
CVE-2024-45604
- EPSS 0.43%
- Veröffentlicht 17.09.2024 20:15:04
- Zuletzt bearbeitet 25.09.2024 19:22:09
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulner...
CVE-2024-45398
- EPSS 0.53%
- Veröffentlicht 17.09.2024 20:15:04
- Zuletzt bearbeitet 25.09.2024 19:20:52
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are a...
CVE-2024-45612
- EPSS 0.3%
- Veröffentlicht 17.09.2024 19:15:28
- Zuletzt bearbeitet 23.09.2024 19:33:04
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to u...
CVE-2024-30262
- EPSS 0.5%
- Veröffentlicht 09.04.2024 17:16:02
- Zuletzt bearbeitet 09.01.2025 17:51:27
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises...
CVE-2024-28235
- EPSS 0.71%
- Veröffentlicht 09.04.2024 16:15:07
- Zuletzt bearbeitet 17.01.2025 15:42:02
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for...
CVE-2024-28191
- EPSS 0.5%
- Veröffentlicht 09.04.2024 14:15:08
- Zuletzt bearbeitet 17.01.2025 15:39:22
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 a...
CVE-2024-28234
- EPSS 0.57%
- Veröffentlicht 09.04.2024 14:15:08
- Zuletzt bearbeitet 02.01.2025 17:49:55
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4...
CVE-2024-28190
- EPSS 0.5%
- Veröffentlicht 09.04.2024 14:15:08
- Zuletzt bearbeitet 16.01.2025 19:54:16
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and p...
CVE-2018-5478
- EPSS 0.41%
- Veröffentlicht 21.09.2023 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:08:52
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.