Contao 是一款开源内容管理系统(CMS)。在版本 4.1.0 至 5.3.50 以及 5.7.0 至 5.7.12 之间,当对包含注册模块的页面发起 POST 请求时, 方法会进入后续的注册处理分支,但并未验证 字段或之前提交的验证码结果。这可能导致 方法调用 发送激活邮件,且该过程缺乏速率限制。因此,未认证的攻击者可以向具有待处理注册状态的邮箱地址重复发送激活邮件,并借此判断该待处理注册是否存在。 此漏洞仅在启用 (注册激活)功能、且目标用户存在未确认的注册记录和待处理的光标选择(opt-in)令牌时才可触
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107845 | 9.3 CRITICAL | Contao: Cross-site scripting in the comments bundle |
| CVE-2026-107842 | 5.3 MEDIUM | Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde |
| CVE-2026-107844 | 5.3 MEDIUM | Contao: Path traversal in the images controller |
| CVE-2026-107851 | 4.3 MEDIUM | Contao: Improper access control in the table access voter |
| CVE-2026-107850 | 4.3 MEDIUM | Contao: Improper access control in the preview links module |
| CVE-2026-107848 | 3.5 LOW | Contao: Cross-site request forgery in custom backend actions |
No comments yet