Contao 是一款开源内容管理系统(CMS)。从版本 4.0.0 至 5.3.50 以及 5.7.12 之前的版本中,未经身份验证的访客可以提交一条评论,其邮箱或网站元数据会在 文件中的 方法中被渲染时,因未进行充分的属性编码和 URL 编码而存在安全风险。当后台用户打开“评论”模块时,攻击者控制的脚本将在该用户的会话上下文中于 Contao 后台域名下执行。由于未发布的评论对管理员(moderator)仍然可见,因此仅依靠审核机制无法防止此漏洞被利用。该问题已在版本 5.3.50 和 5.7.12 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107842 | 5.3 MEDIUM | Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde |
| CVE-2026-107844 | 5.3 MEDIUM | Contao: Path traversal in the images controller |
| CVE-2026-107843 | 5.3 MEDIUM | Contao: The registration module re-sends activation mails on any unauthenticated POST, wit |
| CVE-2026-107851 | 4.3 MEDIUM | Contao: Improper access control in the table access voter |
| CVE-2026-107850 | 4.3 MEDIUM | Contao: Improper access control in the preview links module |
| CVE-2026-107848 | 3.5 LOW | Contao: Cross-site request forgery in custom backend actions |
No comments yet