Where
-Infinity
0
EOL
Feb 14, 2025
Support Ends
Feb 14, 2025

End of life: 2/14/2025, End of support: 2/14/2025, Latest version: 5.4.14

First published (updated )
EOL
Feb 14, 2025
Support Ends
Feb 14, 2025

End of life: 2/14/2025, End of support: 2/14/2025, Latest version: 5.4.14

First published (updated )
Severity
5.3
Input Validation, XSS
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Impact

It is possible to inject insert tags in canonical URLs which will be replaced when the page is rendered.

Patches

Update to Contao 4.13.49, 5.3.15 or 5.4.3.

Workarounds

Disable canonical tags in the settings of the website root page.

References

https://contao.org/en/security-advisories/insert-tag-injection-via-canonical-urls

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 2
Source: GitHub
First published (updated )
Severity
4.3
Path Traversal
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact

Back end users can list files outside their file mounts or the document root in the FileSelector widget.

Patches

Update to Contao 4.13.49.

Workarounds

None.

References

https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Credits

Thanks to Jakob Steeg from usd AG for reporting this vulnerability.

1 / 2
Source: GitHub
First published (updated )
Severity
8.8
Malicious File Upload
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Impact

Back end users with access to the file manager can upload malicious files and execute them on the server.

Patches

Update to Contao 4.13.49, 5.3.15 or 5.4.3.

Workarounds

Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.

References

https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Credits

Thanks to Jakob Steeg from usd AG for reporting this vulnerability.

1 / 2
Source: GitHub
First published (updated )
Severity
7.1
EPSS
0.04%
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Impact

When a front end member changes their password, the corresponding remember-me tokens are not removed.

Patches

Update to Contao 4.13.40.

Workarounds

Disable "Allow auto login" in the login module.

References

https://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 2
Source: GitHub
First published (updated )
Severity
8.4
Infoleak
AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Impact

If the crawler is set to crawl protected pages, it sends the cookie header to externals URLs.

Patches

Update to Contao 4.13.40 or 5.3.4.

Workarounds

Disable crawling protected pages.

References

https://contao.org/en/security-advisories/session-cookie-disclosure-in-the-crawler

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 2
Source: GitHub
First published (updated )
Severity
4.7
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Impact

If BBCode is enabled for comments, users can inject CSS styles.

Patches

Update to Contao 4.13.40 or 5.3.4.

Workarounds

Disable BBCode for comments.

References

https://contao.org/en/security-advisories/insufficient-bbcode-sanitization

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 2
Source: GitHub
First published (updated )
Severity
5.4
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact

It is possible to inject insert tags via the form generator if the submitted form data is output on the page in a specific way.

Patches

Update to Contao 4.13.40 or 5.3.4.

Workarounds

Do not output the submitted form data on the website.

References

https://contao.org/en/security-advisories/insert-tag-injection-via-the-form-generator

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 2
Source: GitHub
First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Impact

Users can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.

Patches

Update to Contao 4.13.40 or Contao 5.3.4.

Workarounds

Disable uploads for untrusted users.

References

https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Credits

Thanks to Alexander Wuttke for reporting this vulnerability.

1 / 2
Source: GitHub
First published (updated )
EOL
Feb 14, 2024
Support Ends
Feb 14, 2024

End of life: 2/14/2024, End of support: 2/14/2024, Latest version: 5.2.10

First published (updated )
EOL
Feb 14, 2024
Support Ends
Feb 14, 2024

End of life: 2/14/2024, End of support: 2/14/2024, Latest version: 5.2.10

First published (updated )
Severity
6.6
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Impact

Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).

Patches

Update to Contao 4.9.42, 4.13.28 or 5.1.10.

Workarounds

Disable login for all untrusted back end users.

References

https://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Credits

Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.

1 / 2
Source: GitHub
First published (updated )
Severity
6.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.

1 / 2
First published (updated )
EOL
Aug 14, 2023
Support Ends
Aug 14, 2023

End of life: 8/14/2023, End of support: 8/14/2023, Latest version: 5.1.11

First published (updated )
EOL
Aug 14, 2023
Support Ends
Aug 14, 2023

End of life: 8/14/2023, End of support: 8/14/2023, Latest version: 5.1.11

First published (updated )
EOL
Feb 14, 2023
Support Ends
Feb 14, 2023

End of life: 2/14/2023, End of support: 2/14/2023, Latest version: 5.0.10

First published (updated )
EOL
Feb 14, 2023
Support Ends
Feb 14, 2023

End of life: 2/14/2023, End of support: 2/14/2023, Latest version: 5.0.10

First published (updated )
Severity
7.2
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Impact

Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).

Patches

Update to Contao 4.13.3.

Workarounds

Disable canonical tags in the root page settings.

References

https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 3
Source: GitHub
First published (updated )
Severity
9.8
OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component phpcli parameter.

First published (updated )
EOL
Jan 14, 2022
Support Ends
Jan 14, 2022

End of life: 1/14/2022, End of support: 1/14/2022, Latest version: 4.12.7

First published (updated )
EOL
Jan 14, 2022
Support Ends
Jan 14, 2022

End of life: 1/14/2022, End of support: 1/14/2022, Latest version: 4.12.7

First published (updated )
Severity
5.9
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Impact

It is possible for untrusted users to inject malicious code into HTML attributes in the back end, which will be executed both in the element preview (back end) and on the website (front end).

Installations are only affected if there are untrusted back end users who have the rights to modify HTML fields (e.g. TinyMCE).

Patches

Update to Contao 4.4.56, 4.9.18 or 4.11.7

Workarounds

Disable all fields that allow HTML for untrusted back end users or disable the login for these users.

References

https://contao.org/en/security-advisories/cross-site-scripting-via-html-attributes-in-the-back-end

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Credits

Thanks to Mikhail Khramenkov and Moritz Vondano for reporting this security issue.

1 / 3
Source: GitHub
First published (updated )
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Impact

It is possible to inject code into the tllog table that will be executed in the browser when the system log is called in the back end.

Patches

Update to Contao 4.9.16 or 4.11.5.

Workarounds

Disable the system log module in the back end for all users (especially admin users).

References

https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 3
Source: GitHub
First published (updated )
EOL
Aug 14, 2021
Support Ends
Aug 14, 2021

End of life: 8/14/2021, End of support: 8/14/2021, Latest version: 4.11.9

First published (updated )
EOL
Aug 14, 2021
Support Ends
Aug 14, 2021

End of life: 8/14/2021, End of support: 8/14/2021, Latest version: 4.11.9

First published (updated )
Severity
5.3
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Impact

It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.

Patches

Update to Contao 4.4.52, 4.9.6 or 4.10.1.

Workarounds

Disable the front end login form and do not use form fields with array keys such as fieldname[].

References

https://contao.org/en/security-advisories/insert-tag-injection-in-forms

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

1 / 3
Source: GitHub
First published (updated )
EOL
Feb 14, 2021
Support Ends
Feb 14, 2021

End of life: 2/14/2021, End of support: 2/14/2021, Latest version: 4.10.7

First published (updated )
EOL
Feb 14, 2021
Support Ends
Feb 14, 2021

End of life: 2/14/2021, End of support: 2/14/2021, Latest version: 4.10.7

First published (updated )
EOL
Feb 14, 2024
Support Ends
Feb 14, 2023

End of life: 2/14/2024, End of support: 2/14/2023, Latest version: 4.9.42

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203