← Back

Contao

contao

43 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Contao
contao
Contao Cms
contao_cms

CVEs (43)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Contao
1Contao
Nov 21, 2024
Mar 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
1Contao
1Contao
Nov 21, 2024
Aug 12, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.
1Contao
1Contao
Nov 21, 2024
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they h...Show more
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.Show less
1Contao
1Contao
Nov 21, 2024
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only...Show more
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you cannot update then disable the login for untrusted back end users.Show less
1Contao
1Contao
Nov 21, 2024
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the...Show more
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.Show less
1Contao
1Contao
Nov 21, 2024
Oct 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
1Contao
1Contao
Nov 21, 2024
Mar 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Contao before 4.5.7 has XSS in the system log.
1Contao
1Contao
Nov 21, 2024
Jan 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
contao prior to 2.11.4 has a sql injection vulnerability
1Contao
1Contao Cms
Nov 21, 2024
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
1Contao
1Contao
Nov 21, 2024
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
1Contao
1Contao
Nov 21, 2024
Dec 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
1Contao
1Contao
Nov 21, 2024
Dec 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
1Contao
1Contao
Nov 21, 2024
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
1Contao
1Contao Cms
Nov 21, 2024
Apr 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
1Contao
1Contao Cms
Nov 21, 2024
Apr 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao 4.7 allows Use of a Key Past its Expiration Date.
1Contao
1Contao Cms
Nov 21, 2024
Apr 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Contao 4.7 allows CSRF.
1Contao
1Contao Cms
Nov 21, 2024
Apr 17, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
1Contao
1Contao Cms
Nov 21, 2024
Apr 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
1Contao
1Contao Cms
May 13, 2026
Jul 21, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
1Contao
1Contao Cms
May 13, 2026
May 26, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.