Vulnerabilities
37 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-65960 +1 in the same advisory: …65961 | Contao is an Open Source CMS. Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method. NVD description · AI analysis pending | 6.6 group max | <1% |
| — | ||
| CVE-2025-57757 | Contao is an Open Source CMS. Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page. NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2025-29790 | Contao is an Open Source CMS. Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2024-45965 | Contao before 5.5.6 allows XSS via an SVG document. Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-45398 | Contao is an Open Source CMS. Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-30262 | Contao is an open source content management system. Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module. NVD description · AI analysis pending | 7.1 group max | <1% |
| — | ||
| CVE-2018-5478 | Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension. Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-36806 | Contao is an open source content management system. Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-29200 | Contao is an open source content management system. Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2022-24899 | Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings. NVD description · AI analysis pending | 6.1 | 4% |
| — | ||
| CVE-2022-26265 | Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. NVD description · AI analysis pending | 9.8 | 30% | PoC |
| — | |
| CVE-2021-35955 | Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2021-37626 +1 in the same advisory: …37627 | Contao is an open source CMS that allows you to create websites and scalable web applications. Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you cannot update then disable the login for untrusted back end users. NVD description · AI analysis pending | 7.2 | 1% |
| — | ||
| CVE-2021-35210 | Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2020-25768 | Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2018-10125 | Contao before 4.5.7 has XSS in the system log. Contao before 4.5.7 has XSS in the system log. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2019-19745 | Contao 4.0 through 4.8.5 allows PHP local file inclusion. Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2019-11512 | Contao 4.x allows SQL Injection. Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2017-16558 | Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module. Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2019-10643 | Contao 4.7 allows Use of a Key Past its Expiration Date. Contao 4.7 allows Use of a Key Past its Expiration Date. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2017-10993 | Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directo Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal. NVD description · AI analysis pending | 8.8 | 2% |
| — |