CVE-2025-57756Sensitive Information Exposure in Contao

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 86.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 28

Description

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A workaround involves disabling the front end search.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDcontao/contao4.10.04.13.56+3
Packagistcontao/contao4.9.144.13.56+2
Packagistcontao/core-bundle4.9.144.13.56+2
CVEListV5contao/contao>= 4.9.14, < 4.13.56, >= 5.0.0-RC1, < 5.3.38, >= 5.4.0-RC1, < 5.6.1+2

Patches

🔴Vulnerability Details

3
CVEList
Contao discloses sensitive information in the front end search index2025-08-28
OSV
Contao discloses sensitive information in the front end search index2025-08-28
GHSA
Contao discloses sensitive information in the front end search index2025-08-28
CVE-2025-57756 — Sensitive Information Exposure | cvebase