<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Contao (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/contao.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/contao-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Contao (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-45398 – Contao is an Open Source CMS. In affected versions a back end user with access t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45398</guid>
    <pubDate>Tue, 17 Sep 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45398</strong></p>
  <p>Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28235 – Contao is an open source content management system. Starting in version 4.9.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28235</guid>
    <pubDate>Tue, 09 Apr 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28235</strong></p>
  <p>Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed  options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protecte…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24899 – Contao is a powerful open source CMS that allows you to create professional webs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24899</guid>
    <pubDate>Fri, 06 May 2022 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24899</strong></p>
  <p>Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26265 – Contao Managed Edition v1.5.0 was discovered to contain a remote command executi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26265</guid>
    <pubDate>Fri, 18 Mar 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26265</strong></p>
  <p>Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37627 – Contao is an open source CMS that allows creation of websites and scalable web a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37627</guid>
    <pubDate>Wed, 11 Aug 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37627</strong></p>
  <p>Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37626 – Contao is an open source CMS that allows you to create websites and scalable web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37626</guid>
    <pubDate>Wed, 11 Aug 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37626</strong></p>
  <p>Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you c…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-4383 – contao prior to 2.11.4 has a sql injection vulnerability</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4383</guid>
    <pubDate>Wed, 29 Jan 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-4383</strong></p>
  <p>contao prior to 2.11.4 has a sql injection vulnerability</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-1860 – Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1860</guid>
    <pubDate>Wed, 08 Jan 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-1860</strong></p>
  <p>Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19745 – Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19745</guid>
    <pubDate>Tue, 17 Dec 2019 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19745</strong></p>
  <p>Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-11512 – Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11512</guid>
    <pubDate>Tue, 09 Jul 2019 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-11512</strong></p>
  <p>Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-16558 – Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16558</guid>
    <pubDate>Thu, 25 Apr 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-16558</strong></p>
  <p>Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10643 – Contao 4.7 allows Use of a Key Past its Expiration Date.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10643</guid>
    <pubDate>Wed, 17 Apr 2019 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10643</strong></p>
  <p>Contao 4.7 allows Use of a Key Past its Expiration Date.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10642 – Contao 4.7 allows CSRF.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10642</guid>
    <pubDate>Wed, 17 Apr 2019 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10642</strong></p>
  <p>Contao 4.7 allows CSRF.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10641 – Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10641</guid>
    <pubDate>Wed, 17 Apr 2019 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10641</strong></p>
  <p>Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-10993 – Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10993</guid>
    <pubDate>Fri, 21 Jul 2017 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-10993</strong></p>
  <p>Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10993">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
