Skip to main content

Vendor archive

contao CVEs

Beta · best-effort

43 CVEs tagged to vendor contao6 Critical, 9 High, 26 Medium, 2 Low, 0 Unrated.

CVE-2025-65961

Published Nov 25, 2025

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed i…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-65960

Published Nov 25, 2025

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57759

Published Aug 28, 2025

Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and artic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57758

Published Aug 28, 2025

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57757

Published Aug 28, 2025

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57756

Published Aug 28, 2025

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29790

Published Mar 18, 2025

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.5…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45965

Published Oct 2, 2024

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x be…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45604

Published Sep 17, 2024

Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45398

Published Sep 17, 2024

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45612

Published Sep 17, 2024

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30262

Published Apr 9, 2024

Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the c…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28235

Published Apr 9, 2024

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao se…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28234

Published Apr 9, 2024

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28191

Published Apr 9, 2024

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-28190

Published Apr 9, 2024

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading f…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5478

Published Sep 21, 2023

Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36806

Published Jul 25, 2023

Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inje…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29200

Published Apr 25, 2023

Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24899

Published May 6, 2022

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26265

Published Mar 18, 2022

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

CVSS 9.8 · Critical
Buzz score
6.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2021-35955

Published Aug 12, 2021

Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37627

Published Aug 11, 2021

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end.…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37626

Published Aug 11, 2021

Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35210

Published Jun 23, 2021

Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the bro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2