Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
Published July 10, 2019.
Contao Contao