Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

contao — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting contao. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Contao is an open-source content management system designed for creating complex, multilingual websites with a focus on accessibility and SEO. Historically, its codebase has been susceptible to several critical vulnerability classes, including remote code execution, cross-site scripting, and SQL injection. These flaws often stem from insufficient input validation and improper access controls within legacy modules. Notable incidents include multiple CVEs allowing attackers to execute arbitrary commands or escalate privileges, frequently exploiting weak session management or insecure file uploads. The platform’s modular architecture sometimes introduces attack surfaces through third-party extensions that lack rigorous security auditing. While recent versions have improved sandboxing and input filtering, the accumulation of 22 recorded CVEs highlights ongoing challenges in maintaining secure code standards across its extensive feature set.

Found 25 results / 25 Clear Filters
Top products by contao: contao
CVE ID Title CVSS Severity Published
CVE-2026-55825 Contao: Possible path traversal in job download URIs — contao CWE-22 3.1 Low 2026-07-31
CVE-2026-55824 Contao crawler leaks auth credentials to external hosts — contao CWE-200 2.6 Low 2026-07-31
CVE-2026-57232 Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module — contao CWE-918 3.1 Low 2026-07-31
CVE-2025-65961 Contao is vulnerable to cross-site scripting in templates — contao CWE-87 3.3 Low 2025-11-25
CVE-2025-65960 Contao is vulnerable to remote code execution in template closures — contao CWE-351 6.6 Medium 2025-11-25
CVE-2025-57759 Contao has improper privilege management for page and article fields — contao CWE-269 4.3 Medium 2025-08-28
CVE-2025-57758 Contao has improper access control in the back end voters — contao CWE-284 4.3 Medium 2025-08-28
CVE-2025-57757 Contao discloses information in the news module — contao CWE-200 5.3 Medium 2025-08-28
CVE-2025-57756 Contao discloses sensitive information in the front end search index — contao CWE-200 5.3 Medium 2025-08-28
CVE-2025-29790 Contao allows cross-site scripting through SVG uploads — contao CWE-79 4.6 - 2025-03-18
CVE-2024-45965 Contao 安全漏洞 — Contao CWE-434 6.4 Medium 2024-10-02
CVE-2024-45604 Directory traversal in the file selector widget in contao/core-bundle — contao CWE-22 4.3 Medium 2024-09-17
CVE-2024-45398 Remote command execution through file upload in contao/core-bundle — contao CWE-434 8.3 High 2024-09-17
CVE-2024-45612 Insert tag injection via canonical URL in Contao — contao CWE-20 5.3 Medium 2024-09-17
CVE-2024-30262 Contao's remember-me tokens will not be cleared after a password change — contao CWE-613 5.9 Medium 2024-04-09
CVE-2024-28235 Contao possible cookie sharing with external domains while checking protected pages for broken links — contao CWE-200 8.4 High 2024-04-09
CVE-2024-28234 Contao has insufficient BBCode sanitizer — contao CWE-74 4.3 Medium 2024-04-09
CVE-2024-28191 Contao may have unencoded insert tags in the frontend — contao CWE-74 3.1 Low 2024-04-09
CVE-2024-28190 Contao core bundle vulnerable to cross site scripting in the file manager — contao CWE-79 5.4 Medium 2024-04-09
CVE-2023-36806 Contao cross site scripting vulnerability via input unit widget — contao CWE-79 6.5 Medium 2023-07-25
CVE-2023-29200 contao/core-bundle has path traversal vulnerability in the file manager — contao CWE-22 4.3 Medium 2023-04-25
CVE-2022-24899 Cross site scripting via canonical tag — contao CWE-79 7.2 High 2022-05-05
CVE-2021-37627 Privilege escalation via form generator — contao CWE-269 8.0 High 2021-08-11
CVE-2021-37626 PHP file inclusion via insert tags — contao CWE-94 7.2 High 2021-08-11
CVE-2012-4383 contao SQL注入漏洞 — contao 8.8 - 2020-01-29

This page lists every published CVE security advisory associated with contao. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.