CVEs we hold for Contao
Records whose assigning authority named Contao as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-57232Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Modulecontao CVE-2026-55825Contao: Possible path traversal in job download URIscontao CVE-2026-55824Contao crawler leaks auth credentials to external hostscontao CVE-2025-65961Contao is vulnerable to cross-site scripting in templatescontao CVE-2025-65960Contao is vulnerable to remote code execution in template closurescontao CVE-2025-57759Contao has improper privilege management for page and article fieldscontao CVE-2025-57758Contao has improper access control in the back end voterscontao CVE-2025-57756Contao discloses sensitive information in the front end search indexcontao CVE-2025-29790Contao allows cross-site scripting through SVG uploadscontao CVE-2024-45604Directory traversal in the file selector widget in contao/core-bundlecontao CVE-2024-45398Remote command execution through file upload in contao/core-bundlecontao CVE-2024-30262Contao's remember-me tokens will not be cleared after a password changecontao CVE-2024-28235Contao possible cookie sharing with external domains while checking protected pages for broken linkscontao CVE-2024-28191Contao may have unencoded insert tags in the frontendcontao CVE-2024-28190Contao core bundle vulnerable to cross site scripting in the file managercontao CVE-2023-36806Contao cross site scripting vulnerability via input unit widgetcontao CVE-2023-29200contao/core-bundle has path traversal vulnerability in the file managercontao 25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.