Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
contao vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2019-19745
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server....
Contao Contao 4.0
Contao Contao 4.1
Contao Contao 4.2
Contao Contao 4.3
Contao Contao
Contao Contao 4.5
Contao Contao 4.6
Contao Contao 4.7
5.3
CVSSv3
CVE-2019-19712
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them....
Contao Contao 4.0
Contao Contao 4.1
Contao Contao 4.2
Contao Contao 4.3
Contao Contao
Contao Contao 4.5
Contao Contao 4.6
Contao Contao 4.7
5.3
CVSSv3
CVE-2020-25768
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered....
Contao Contao
9.8
CVSSv3
CVE-2014-1860
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities...
Contao Contao Cms
NA
CVE-2011-0508
Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by...
Contao Contao Cms 2.9.2
4.3
CVSSv3
CVE-2015-0269
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors....
Contao Contao Cms
Contao Contao Cms 3.4.2
Contao Contao Cms 3.4.0
Contao Contao Cms 3.4.1
Contao Contao Cms 3.4.3
8.8
CVSSv3
CVE-2019-10642
Contao 4.7 allows CSRF....
Contao Contao Cms 4.7.0
9.8
CVSSv3
CVE-2019-10641
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password....
Contao Contao Cms
9.8
CVSSv3
CVE-2017-16558
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module....
Contao Contao Cms
9.8
CVSSv3
CVE-2022-26265
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter....
Contao Contao 1.5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-29214
CVE-2022-29432
CVE-2022-1388
LFI
CVE-2022-1813
SSRF
CVE-2022-20821
CVE-2021-41834
XML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »