Contao
This hub aggregates every CVE we track for Contao, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
35
CVEs tracked
2
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM21HIGH7LOW5CRITICAL2
Monthly trend
3
1
0
0
0
0
1
0
0
0
0
4
0
0
2
0
0
0
0
0
0
0
3
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Contao.
- CVE-2026-55825Contao: Possible path traversal in job download URIs3.1
- CVE-2026-55824Contao crawler leaks auth credentials to external hosts2.6
- CVE-2026-57232Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module3.1
- CVE-2025-65961Contao is vulnerable to cross-site scripting in templates3.3
- CVE-2025-65960Contao is vulnerable to remote code execution in template closures6.6
- CVE-2025-57759Contao has improper privilege management for page and article fields4.3
- CVE-2025-57758Contao has improper access control in the back end voters4.3
- CVE-2025-57757Contao discloses information in the news module5.3
- CVE-2025-57756Contao discloses sensitive information in the front end search index5.3
- CVE-2025-29790Contao allows cross-site scripting through SVG uploads5.4
- CVE-2024-45965Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.6.4
- CVE-2024-45604Directory traversal in the file selector widget in contao/core-bundle4.3
- CVE-2024-45398Remote command execution through file upload in contao/core-bundle8.3
- CVE-2024-45612Insert tag injection via canonical URL in Contao5.3
- CVE-2024-30262Contao's remember-me tokens will not be cleared after a password change5.9
Product normalization is registry-driven with AI assist and human review. How it works