Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Contao Subscribe
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-10641 1 Contao 1 Contao Cms 2019-04-19 5.0 MEDIUM 9.8 CRITICAL
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
CVE-2019-10642 1 Contao 1 Contao Cms 2019-04-18 6.8 MEDIUM 8.8 HIGH
Contao 4.7 allows CSRF.
CVE-2011-0508 1 Contao 1 Contao Cms 2018-10-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
CVE-2015-0269 1 Contao 1 Contao Cms 2017-06-08 4.0 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.