Vulnerabilities

Last updated 55 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
contao/core-bundle Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module Low Risk 3.1 3 days ago 3 days ago
contao/core-bundle Contao: Unencoded insert tags in the frontend Low Risk 3.1 2 years ago 18 days ago
contao/core-bundle Contao: Possible cookie sharing with external domains while checking protected pages for broken links High Risk 8.3 2 years ago 18 days ago
contao/core-bundle Contao: Remember-me tokens will not be cleared after a password change Medium Risk 5.9 2 years ago 18 days ago
contao/core-bundle Contao: Cross site scripting in the file manager Medium Risk 5.4 2 years ago 18 days ago
contao/core-bundle Cross site scripting via input unit widget Medium Risk 6.6 3 years ago 18 days ago
contao/core-bundle Cross site scripting in the system log Medium Risk 6.1 5 years ago 18 days ago
contao/core-bundle Contao: Possible path traversal in job download URIs Low Risk 3.1 1 month ago 1 month ago
contao/core-bundle Contao crawler leaks auth credentials to external hosts Low Risk 2.6 1 month ago 1 month ago
contao/core-bundle Privilege escalation via form generator High Risk 8.0 5 years ago 2 months ago
contao/core-bundle Cross site scripting via HTML attributes in the back end Medium Risk 5.9 5 years ago 2 months ago
contao/core-bundle PHP file inclusion via insert tags Medium Risk 6.7 5 years ago 2 months ago
contao/core-bundle Contao is vulnerable to cross-site scripting in templates Low Risk 3.3 10 months ago 9 months ago
contao/core-bundle Contao is vulnerable to remote code execution in template closures Medium Risk 6.6 10 months ago 10 months ago
contao/core-bundle Contao applies improper access control in the back end voters Medium Risk 4.3 1 year ago 1 year ago
contao/core-bundle Contao does not properly manage privileges for page and article fields Medium Risk 4.3 1 year ago 1 year ago
contao/core-bundle Contao can disclose sensitive information in the news module Medium Risk 5.3 1 year ago 1 year ago
contao/core-bundle Contao discloses sensitive information in the front end search index Medium Risk 5.3 1 year ago 1 year ago
contao/core-bundle Cross site scripting via canonical tag in Contao High Risk 7.2 4 years ago 1 year ago
contao/core-bundle Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads Medium Risk 6.0 1 year ago 1 year ago
contao/core-bundle Contao affected by insert tag injection via canonical URL Medium Risk 5.3 2 years ago 2 years ago
contao/core-bundle Contao affected by remote command execution through file upload High Risk 8.3 2 years ago 2 years ago
contao/core-bundle Contao affected by directory traversal in the file selector widget Medium Risk 4.3 2 years ago 2 years ago
contao/core-bundle Contao Does Not Expire Tokens Correctly Critical 9.8 4 years ago 2 years ago
contao/core-bundle Contao Does Not Invalidate Existing Sessions When Password Changes Critical 9.8 4 years ago 2 years ago
contao/core-bundle Contao Core directory traversal vulnerability High Risk 8.8 4 years ago 2 years ago
contao/core-bundle Contao CSRF Token Bypass High Risk 8.8 4 years ago 2 years ago
contao/core-bundle Contao SQL injection in the file manager Critical 9.8 4 years ago 2 years ago
contao/core-bundle Contao SQL injection in the backend and listing module Critical 9.8 4 years ago 2 years ago
contao/core-bundle Insert tag injection in the Contao login module Medium Risk 5.3 6 years ago 2 years ago
contao/core-bundle Information disclosure in the Contao backend Medium Risk 5.3 6 years ago 2 years ago
contao/core-bundle Contao Insert tag injection in forms Medium Risk 5.3 6 years ago 2 years ago
contao/core-bundle Unrestricted file uploads in Contao High Risk 8.8 6 years ago 2 years ago
contao/core-bundle Cross-site Scripting in Contao Medium Risk 6.1 4 years ago 2 years ago