Vulnerabilities
Last updated 55 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module | Low Risk 3.1 | 3 days ago | 3 days ago |
|
|
Contao: Unencoded insert tags in the frontend | Low Risk 3.1 | 2 years ago | 18 days ago |
|
|
Contao: Possible cookie sharing with external domains while checking protected pages for broken links | High Risk 8.3 | 2 years ago | 18 days ago |
|
|
Contao: Remember-me tokens will not be cleared after a password change | Medium Risk 5.9 | 2 years ago | 18 days ago |
|
|
Contao: Cross site scripting in the file manager | Medium Risk 5.4 | 2 years ago | 18 days ago |
|
|
Cross site scripting via input unit widget | Medium Risk 6.6 | 3 years ago | 18 days ago |
|
|
Cross site scripting in the system log | Medium Risk 6.1 | 5 years ago | 18 days ago |
|
|
Contao: Possible path traversal in job download URIs | Low Risk 3.1 | 1 month ago | 1 month ago |
|
|
Contao crawler leaks auth credentials to external hosts | Low Risk 2.6 | 1 month ago | 1 month ago |
|
|
Privilege escalation via form generator | High Risk 8.0 | 5 years ago | 2 months ago |
|
|
Cross site scripting via HTML attributes in the back end | Medium Risk 5.9 | 5 years ago | 2 months ago |
|
|
PHP file inclusion via insert tags | Medium Risk 6.7 | 5 years ago | 2 months ago |
|
|
Contao is vulnerable to cross-site scripting in templates | Low Risk 3.3 | 10 months ago | 9 months ago |
|
|
Contao is vulnerable to remote code execution in template closures | Medium Risk 6.6 | 10 months ago | 10 months ago |
|
|
Contao applies improper access control in the back end voters | Medium Risk 4.3 | 1 year ago | 1 year ago |
|
|
Contao does not properly manage privileges for page and article fields | Medium Risk 4.3 | 1 year ago | 1 year ago |
|
|
Contao can disclose sensitive information in the news module | Medium Risk 5.3 | 1 year ago | 1 year ago |
|
|
Contao discloses sensitive information in the front end search index | Medium Risk 5.3 | 1 year ago | 1 year ago |
|
|
Cross site scripting via canonical tag in Contao | High Risk 7.2 | 4 years ago | 1 year ago |
|
|
Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads | Medium Risk 6.0 | 1 year ago | 1 year ago |
|
|
Contao affected by insert tag injection via canonical URL | Medium Risk 5.3 | 2 years ago | 2 years ago |
|
|
Contao affected by remote command execution through file upload | High Risk 8.3 | 2 years ago | 2 years ago |
|
|
Contao affected by directory traversal in the file selector widget | Medium Risk 4.3 | 2 years ago | 2 years ago |
|
|
Contao Does Not Expire Tokens Correctly | Critical 9.8 | 4 years ago | 2 years ago |
|
|
Contao Does Not Invalidate Existing Sessions When Password Changes | Critical 9.8 | 4 years ago | 2 years ago |
|
|
Contao Core directory traversal vulnerability | High Risk 8.8 | 4 years ago | 2 years ago |
|
|
Contao CSRF Token Bypass | High Risk 8.8 | 4 years ago | 2 years ago |
|
|
Contao SQL injection in the file manager | Critical 9.8 | 4 years ago | 2 years ago |
|
|
Contao SQL injection in the backend and listing module | Critical 9.8 | 4 years ago | 2 years ago |
|
|
Insert tag injection in the Contao login module | Medium Risk 5.3 | 6 years ago | 2 years ago |
|
|
Information disclosure in the Contao backend | Medium Risk 5.3 | 6 years ago | 2 years ago |
|
|
Contao Insert tag injection in forms | Medium Risk 5.3 | 6 years ago | 2 years ago |
|
|
Unrestricted file uploads in Contao | High Risk 8.8 | 6 years ago | 2 years ago |
|
|
Cross-site Scripting in Contao | Medium Risk 6.1 | 4 years ago | 2 years ago |
Page 1