Skip to main content

Vendor archive

contao CVEs

Beta · best-effort

43 CVEs tagged to vendor contao6 Critical, 9 High, 26 Medium, 2 Low, 0 Unrated.

CVE-2020-25768

Published Oct 7, 2020

Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced w…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19745

Published Dec 17, 2019

Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19714

Published Dec 17, 2019

Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19712

Published Dec 17, 2019

Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11512

Published Jul 9, 2019

Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16558

Published Apr 25, 2019

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10641

Published Apr 17, 2019

Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20028

Published Apr 17, 2019

Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10993

Published Jul 21, 2017

Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0269

Published May 26, 2017

Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the docum…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1297

Published Mar 19, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4335

Published Nov 28, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0508

Published Jan 20, 2011

Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-43 of 43 CVEsPage 2 of 2