Contao/core-bundle
This hub aggregates every CVE we track for Contao/core-bundle, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
31
CVEs tracked
4
Critical
8
High
0
In CISA KEV
Severity distribution
MEDIUM17HIGH8CRITICAL4LOW2
Monthly trend
0
0
3
0
0
0
0
0
1
0
0
0
0
4
0
0
2
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Contao/core-bundle.
- CVE-2025-65961Contao is vulnerable to cross-site scripting in templates3.3
- CVE-2025-65960Contao is vulnerable to remote code execution in template closures6.6
- CVE-2025-57759Contao has improper privilege management for page and article fields4.3
- CVE-2025-57758Contao has improper access control in the back end voters4.3
- CVE-2025-57757Contao discloses information in the news module5.3
- CVE-2025-57756Contao discloses sensitive information in the front end search index5.3
- CVE-2025-29790Contao allows cross-site scripting through SVG uploads5.4
- CVE-2024-45604Directory traversal in the file selector widget in contao/core-bundle4.3
- CVE-2024-45398Remote command execution through file upload in contao/core-bundle8.3
- CVE-2024-45612Insert tag injection via canonical URL in Contao5.3
- CVE-2024-30262Contao's remember-me tokens will not be cleared after a password change5.9
- CVE-2024-28235Contao possible cookie sharing with external domains while checking protected pages for broken links8.3
- CVE-2024-28191Contao may have unencoded insert tags in the frontend3.1
- CVE-2024-28190Contao core bundle vulnerable to cross site scripting in the file manager5.4
- CVE-2023-36806Contao cross site scripting vulnerability via input unit widget6.5
Product normalization is registry-driven with AI assist and human review. How it works