Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
Contao before 4.5.7 has XSS in the system log.
Contao 3.x before 3.5.32 allows Cross-site Scripting (XSS) via the unsubscribe module in the frontend newsletter extension.