contao/core-bundle
Packagist28 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting contao/core-bundlepage 1 of 1
- CVE-2017-10993HIGHCVSS 8.8EG 8.8✓ Fixed in 4.4.12017-07-21
vulnerable: 4.0.0 ... 4.4.0-beta1 (36 versions)
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
- CVE-2017-16558CRITICALCVSS 9.8EG 9.82019-04-25
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
- CVE-2018-10125MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.5.352020-03-16
Contao before 4.5.7 has XSS in the system log.
- CVE-2019-10641CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.7.32019-04-17
vulnerable: 4.5.0 ... 4.7.2 (40 versions)
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
- CVE-2019-10642HIGHCVSS 8.8EG 8.8✓ Fixed in 4.7.32019-04-17
vulnerable: 4.7.0, 4.7.1, 4.7.2
Contao 4.7 allows CSRF.
- CVE-2019-10643CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.7.32019-04-17
vulnerable: 4.7.0, 4.7.1, 4.7.2
Contao 4.7 allows Use of a Key Past its Expiration Date.
- CVE-2019-11512CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.7.52019-07-09
vulnerable: 4.5.0 ... 4.7.4 (42 versions)
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
- CVE-2019-19712MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.8.62019-12-17
vulnerable: 4.5.0 ... 4.8.5 (53 versions)
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
- CVE-2019-19714MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.8.62019-12-17
vulnerable: 4.8.4, 4.8.5
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
- CVE-2019-19745HIGHCVSS 8.8EG 8.8✓ Fixed in 4.8.62019-12-17
vulnerable: 4.5.0 ... 4.8.5 (53 versions)
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
- CVE-2020-25768MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.10.12020-10-07
vulnerable: 4.10.0
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
- CVE-2021-35210MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.11.52021-06-23
vulnerable: 4.10.0 ... 4.11.4 (15 versions)
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
- CVE-2021-35955MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.11.72021-08-12
vulnerable: 4.10.0 ... 4.11.6 (17 versions)
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.
- CVE-2021-37626HIGHCVSS 7.2EG 7.2✓ Fixed in 4.11.72021-08-11
vulnerable: 4.10.0 ... 4.11.6 (17 versions)
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they ha…
- CVE-2021-37627HIGHCVSS 8.0EG 8.0✓ Fixed in 4.11.72021-08-11
vulnerable: 4.10.0 ... 4.11.6 (17 versions)
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back …
- CVE-2022-24899HIGHCVSS 7.2EG 7.2✓ Fixed in 4.13.32022-05-06
vulnerable: 4.13.0, 4.13.1, 4.13.2
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disab…
- CVE-2023-36806MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.1.102023-07-25
vulnerable: 5.0.0 ... 5.1.9 (24 versions)
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, whic…
- CVE-2024-28190MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.3.42024-04-09
vulnerable: 5.0.0 ... 5.3.3 (55 versions)
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in too…
- CVE-2024-28191LOWCVSS 3.1EG 3.1✓ Fixed in 5.3.42024-04-09
vulnerable: 5.0.0 ... 5.3.3 (55 versions)
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao version…
- CVE-2024-28235HIGHCVSS 8.3EG 8.3✓ Fixed in 5.3.42024-04-09
vulnerable: 5.0.0 ... 5.3.3 (55 versions)
Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed …
- CVE-2024-30262MEDIUMCVSS 5.9EG 5.9✓ Fixed in 4.13.402024-04-09
vulnerable: 4.0.0 ... 4.9.9 (279 versions)
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone …
- CVE-2024-45398HIGHCVSS 8.3EG 8.3✓ Fixed in 5.4.32024-09-17
vulnerable: 5.4.0, 5.4.1, 5.4.2
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to u…
- CVE-2024-45604MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.13.492024-09-17
vulnerable: 4.0.0 ... 4.9.9 (288 versions)
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for …
- CVE-2024-45612MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.4.32024-09-17
vulnerable: 5.4.0, 5.4.1, 5.4.2
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users …
- CVE-2025-57756MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.13.562025-08-28
vulnerable: 4.10.0 ... 4.9.42 (123 versions)
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue…
- CVE-2025-57757MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.3.382025-08-28
vulnerable: 5.0.0 ... 5.3.9 (89 versions)
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has b…
- CVE-2025-65960MEDIUMCVSS 6.6EG 6.6✓ Fixed in 4.13.572025-11-25
vulnerable: 4.0.0 ... 4.9.9 (294 versions)
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required p…
- CVE-2025-65961LOWCVSS 3.3EG 3.3✓ Fixed in 4.13.572025-11-25
vulnerable: 4.0.0 ... 4.9.9 (294 versions)
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has …
Check whether contao/core-bundle is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for contao/core-bundle CVEs against the assets you own.
Start Free Scan →