Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2012-4383
- EPSS 0.92%
- Veröffentlicht 29.01.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:42:46
contao prior to 2.11.4 has a sql injection vulnerability
8.8
CVE-2019-19745
- EPSS 1.11%
- Veröffentlicht 17.12.2019 15:15:25
- Zuletzt bearbeitet 21.11.2024 04:35:18
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
5.3
CVE-2019-19714
- EPSS 0.82%
- Veröffentlicht 17.12.2019 15:15:25
- Zuletzt bearbeitet 21.11.2024 04:35:14
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
5.3
CVE-2019-19712
- EPSS 0.88%
- Veröffentlicht 17.12.2019 14:15:18
- Zuletzt bearbeitet 21.11.2024 04:35:14
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
9.8
CVE-2019-11512
- EPSS 1.46%
- Veröffentlicht 09.07.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:14
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.