Filtered by vendor Contao
                        
                        Subscribe
                        
                        
                    
                    
                
                    Total
                    24 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 | 
|---|---|---|---|---|---|
| CVE-2019-10641 | 1 Contao | 1 Contao Cms | 2019-04-19 | 5.0 MEDIUM | 9.8 CRITICAL | 
| Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password. | |||||
| CVE-2019-10642 | 1 Contao | 1 Contao Cms | 2019-04-18 | 6.8 MEDIUM | 8.8 HIGH | 
| Contao 4.7 allows CSRF. | |||||
| CVE-2011-0508 | 1 Contao | 1 Contao Cms | 2018-10-09 | 4.3 MEDIUM | N/A | 
| Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php. | |||||
| CVE-2015-0269 | 1 Contao | 1 Contao Cms | 2017-06-08 | 4.0 MEDIUM | 4.3 MEDIUM | 
| Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors. | |||||
