← Back

Contao

contao

Vendor: Contao • 32 CVEs

CVEs (32)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Contao
1Contao
Nov 21, 2024
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
1Contao
1Contao
Nov 21, 2024
Aug 12, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.
1Contao
1Contao
Nov 21, 2024
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they h...Show more
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.Show less
1Contao
1Contao
Nov 21, 2024
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only...Show more
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you cannot update then disable the login for untrusted back end users.Show less
1Contao
1Contao
Nov 21, 2024
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the...Show more
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.Show less
1Contao
1Contao
Nov 21, 2024
Oct 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
1Contao
1Contao
Nov 21, 2024
Mar 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Contao before 4.5.7 has XSS in the system log.
1Contao
1Contao
Nov 21, 2024
Jan 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
contao prior to 2.11.4 has a sql injection vulnerability
1Contao
1Contao
Nov 21, 2024
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
1Contao
1Contao
Nov 21, 2024
Dec 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
1Contao
1Contao
Nov 21, 2024
Dec 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
1Contao
1Contao
Nov 21, 2024
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.