contao/core-bundle
Packagist40 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting contao/core-bundlepage 1 of 1
- CVE-2017-10993HIGHCVSS 8.8EG 8.8fixed in 4.4.12017-07-21
vulnerable: 4.0.0 ... 4.4.0-beta1 (36 versions)
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
- CVE-2017-16558CRITICALCVSS 9.8EG 9.8fixed in 4.4.82019-04-25
vulnerable: 4.0.0 ... 4.4.7 (43 versions)
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
- CVE-2018-10125MEDIUMCVSS 6.1EG 6.1fixed in 4.4.18, 4.5.8 or 3.5.35, by version range2020-03-16
vulnerable: 4.5.0 ... 4.5.7 (8 versions)
Contao before 4.5.7 has XSS in the system log.
- CVE-2019-10641CRITICALCVSS 9.8EG 9.8fixed in 4.4.37 or 4.7.3, by version range2019-04-17
vulnerable: 4.5.0 ... 4.7.2 (40 versions)
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
- CVE-2019-10642HIGHCVSS 8.8EG 8.8fixed in 4.7.32019-04-17
vulnerable: 4.7.0, 4.7.1, 4.7.2
Contao 4.7 allows CSRF.
- CVE-2019-10643CRITICALCVSS 9.8EG 9.8fixed in 4.7.32019-04-17
vulnerable: 4.7.0, 4.7.1, 4.7.2
Contao 4.7 allows Use of a Key Past its Expiration Date.
- CVE-2019-11512CRITICALCVSS 9.8EG 9.8fixed in 4.4.39 or 4.7.5, by version range2019-07-09
vulnerable: 4.5.0 ... 4.7.4 (42 versions)
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
- CVE-2019-19712MEDIUMCVSS 5.3EG 5.3fixed in 4.4.46 or 4.8.6, by version range2019-12-17
vulnerable: 4.5.0 ... 4.8.5 (53 versions)
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
- CVE-2019-19714MEDIUMCVSS 5.3EG 5.3fixed in 4.8.62019-12-17
vulnerable: 4.8.4, 4.8.5
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
- CVE-2019-19745HIGHCVSS 8.8EG 8.8fixed in 4.4.46 or 4.8.6, by version range2019-12-17
vulnerable: 4.5.0 ... 4.8.5 (53 versions)
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
- CVE-2020-25768MEDIUMCVSS 5.3EG 5.3fixed in 4.4.52, 4.9.6 or 4.10.1, by version range2020-10-07
vulnerable: 4.10.0
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
- CVE-2021-35210MEDIUMCVSS 6.1EG 6.1fixed in 4.9.16 or 4.11.5, by version range2021-06-23
vulnerable: 4.10.0 ... 4.11.4 (15 versions)
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
- CVE-2021-35955MEDIUMCVSS 4.8EG 4.8fixed in 4.4.56, 4.9.18 or 4.11.7, by version range2021-08-12
vulnerable: 4.10.0 ... 4.11.6 (17 versions)
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.
- CVE-2021-37626HIGHCVSS 7.2EG 7.2fixed in 4.4.56, 4.9.18 or 4.11.7, by version range2021-08-11
vulnerable: 4.10.0 ... 4.11.6 (17 versions)
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they ha…
- CVE-2021-37627HIGHCVSS 8.0EG 8.0fixed in 4.4.56, 4.9.18 or 4.11.7, by version range2021-08-11
vulnerable: 4.10.0 ... 4.11.6 (17 versions)
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back …
- CVE-2022-24899HIGHCVSS 7.2EG 7.2fixed in 4.13.32022-05-06
vulnerable: 4.13.0, 4.13.1, 4.13.2
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disab…
- CVE-2023-36806MEDIUMCVSS 6.5EG 6.5fixed in 4.9.42, 4.13.28 or 5.1.10, by version range2023-07-25
vulnerable: 5.0.0 ... 5.1.9 (24 versions)
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, whic…
- CVE-2024-28190MEDIUMCVSS 5.4EG 5.4fixed in 4.13.40 or 5.3.4, by version range2024-04-09
vulnerable: 5.0.0 ... 5.3.3 (55 versions)
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in too…
- CVE-2024-28191LOWCVSS 3.1EG 3.1fixed in 4.13.40 or 5.3.4, by version range2024-04-09
vulnerable: 5.0.0 ... 5.3.3 (55 versions)
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao version…
- CVE-2024-28235HIGHCVSS 8.3EG 8.3fixed in 4.13.40 or 5.3.4, by version range2024-04-09
vulnerable: 5.0.0 ... 5.3.3 (55 versions)
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed …
- CVE-2024-30262MEDIUMCVSS 5.9EG 5.9fixed in 4.13.402024-04-09
vulnerable: 4.0.0 ... 4.9.9 (279 versions)
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone …
- CVE-2024-45398HIGHCVSS 8.3EG 8.3fixed in 4.13.49, 5.3.15 or 5.4.3, by version range2024-09-17
vulnerable: 5.4.0, 5.4.1, 5.4.2
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to u…
- CVE-2024-45604MEDIUMCVSS 4.3EG 4.3fixed in 4.13.492024-09-17
vulnerable: 4.0.0 ... 4.9.9 (288 versions)
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for …
- CVE-2024-45612MEDIUMCVSS 5.3EG 5.3fixed in 4.13.49, 5.3.15 or 5.4.3, by version range2024-09-17
vulnerable: 5.4.0, 5.4.1, 5.4.2
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users …
- CVE-2025-29790MEDIUMCVSS 5.4EG 5.4fixed in 4.13.54, 5.3.30 or 5.5.6, by version range2025-03-18
vulnerable: 5.4.0 ... 5.5.5 (25 versions)
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
- CVE-2025-57756MEDIUMCVSS 5.3EG 5.3fixed in 4.13.56, 5.3.38 or 5.6.1, by version range2025-08-28
vulnerable: 5.4.0 ... 5.6.0-RC3 (44 versions)
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue…
- CVE-2025-57757MEDIUMCVSS 5.3EG 5.3fixed in 5.3.38 or 5.6.1, by version range2025-08-28
vulnerable: 5.4.0 ... 5.6.0-RC3 (44 versions)
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has b…
- CVE-2025-57758MEDIUMCVSS 4.3EG 4.3fixed in 5.3.38 or 5.6.1, by version range2025-08-28
vulnerable: 5.4.0 ... 5.6.0-RC3 (44 versions)
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versi…
- CVE-2025-57759MEDIUMCVSS 4.3EG 4.3fixed in 5.3.38 or 5.6.1, by version range2025-08-28
vulnerable: 5.4.0 ... 5.6.0-RC3 (44 versions)
Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has…
- CVE-2025-65960MEDIUMCVSS 6.6EG 6.6fixed in 4.13.57, 5.3.42 or 5.6.5, by version range2025-11-25
vulnerable: 5.4.0 ... 5.6.4 (48 versions)
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required p…
- CVE-2025-65961MEDIUMCVSS 4.8EG 4.8fixed in 4.13.57, 5.3.42 or 5.6.5, by version range2025-11-25
vulnerable: 5.4.0 ... 5.6.4 (48 versions)
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has …
- CVE-2026-107842MEDIUMCVSS 5.3EG 5.3fixed in 5.3.50 or 5.7.12, by version range2026-10-09
vulnerable: 4.0.0 ... 5.3.9 (397 versions)
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, URLs, and indexed context snippets to unauthenticated visitors when contao.search.index_protected is changed from en…
- CVE-2026-107843MEDIUMCVSS 5.3EG 5.3fixed in 5.3.50 or 5.7.12, by version range2026-10-09
vulnerable: 4.1.0 ... 5.3.9 (390 versions)
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the …
- CVE-2026-107844MEDIUMCVSS 5.3EG 5.3fixed in 5.3.50 or 5.7.12, by version range2026-10-09
vulnerable: 4.1.0 ... 5.3.9 (390 versions)
Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify …
- CVE-2026-107848LOWCVSS 3.5EG 3.5fixed in 5.3.50 or 5.7.12, by version range2026-10-09
vulnerable: 4.0.0 ... 5.3.9 (397 versions)
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions disp…
- CVE-2026-107850MEDIUMCVSS 4.3EG 4.3fixed in 5.7.122026-10-09
vulnerable: 5.7.1 ... 5.7.9 (11 versions)
Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter although the shipped class is PreviewVo…
- CVE-2026-107851MEDIUMCVSS 4.3EG 4.3fixed in 5.7.122026-10-09
vulnerable: 5.7.0 ... 5.7.9 (12 versions)
Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the u…
- CVE-2026-55824LOWCVSS 2.6EG 2.6fixed in 5.3.47 or 5.7.7, by version range2026-07-31
vulnerable: 5.4.0 ... 5.7.6 (62 versions)
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to exter…
- CVE-2026-55825LOWCVSS 3.1EG 3.1fixed in 5.7.72026-07-31
vulnerable: 5.7.0 ... 5.7.6 (7 versions)
Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file from…
- CVE-2026-57232LOWCVSS 3.1EG 3.1fixed in 5.3.48 or 5.7.9, by version range2026-07-31
vulnerable: 5.4.0 ... 5.7.8 (64 versions)
Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or privat…
Check whether contao/core-bundle is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for contao/core-bundle CVEs against the assets you own.
Book a Demo →