Skip to main content

Vendor/product archive

contao / contao_cms CVEs

Beta · best-effort

11 CVEs tagged to contao / contao_cms4 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2017-16558

Published Apr 25, 2019

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10641

Published Apr 17, 2019

Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20028

Published Apr 17, 2019

Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10993

Published Jul 21, 2017

Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0269

Published May 26, 2017

Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the docum…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1297

Published Mar 19, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4335

Published Nov 28, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0508

Published Jan 20, 2011

Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1