vciy

CVEs we hold for Contao

Records whose assigning authority named Contao as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-57232Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Modulecontao
CVE-2026-55825Contao: Possible path traversal in job download URIscontao
CVE-2026-55824Contao crawler leaks auth credentials to external hostscontao
CVE-2025-65961Contao is vulnerable to cross-site scripting in templatescontao
CVE-2025-65960Contao is vulnerable to remote code execution in template closurescontao
CVE-2025-57759Contao has improper privilege management for page and article fieldscontao
CVE-2025-57758Contao has improper access control in the back end voterscontao
CVE-2025-57757Contao discloses information in the news modulecontao
CVE-2025-57756Contao discloses sensitive information in the front end search indexcontao
CVE-2025-29790Contao allows cross-site scripting through SVG uploadscontao
CVE-2024-45965no title heldContao
CVE-2024-45612Insert tag injection via canonical URL in Contaocontao
CVE-2024-45604Directory traversal in the file selector widget in contao/core-bundlecontao
CVE-2024-45398Remote command execution through file upload in contao/core-bundlecontao
CVE-2024-30262Contao's remember-me tokens will not be cleared after a password changecontao
CVE-2024-28235Contao possible cookie sharing with external domains while checking protected pages for broken linkscontao
CVE-2024-28234Contao has insufficient BBCode sanitizercontao
CVE-2024-28191Contao may have unencoded insert tags in the frontendcontao
CVE-2024-28190Contao core bundle vulnerable to cross site scripting in the file managercontao
CVE-2023-36806Contao cross site scripting vulnerability via input unit widgetcontao
CVE-2023-29200contao/core-bundle has path traversal vulnerability in the file managercontao
CVE-2022-24899Cross site scripting via canonical tagcontao
CVE-2021-37627Privilege escalation via form generatorcontao
CVE-2021-37626PHP file inclusion via insert tagscontao
CVE-2012-4383no title heldcontao

25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.