Contao Cms vulnerabilities

10 known vulnerabilities affecting contao/contao_cms.

Total CVEs
10
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2014-1860CRITICALCVSS 9.8≤ 3.2.42020-01-08
CVE-2014-1860 [CRITICAL] CWE-502 CVE-2014-1860: Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
nvd
CVE-2017-16558CRITICALCVSS 9.8≥ 3.0.0, ≤ 3.5.30≥ 4.0.0, ≤ 4.4.72019-04-25
CVE-2017-16558 [CRITICAL] CWE-89 CVE-2017-16558: Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
nvd
CVE-2019-10641CRITICALCVSS 9.8fixed in 3.5.39≥ 4.0.0, < 4.7.32019-04-17
CVE-2019-10641 [CRITICAL] CWE-640 CVE-2019-10641: Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Pas Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
nvd
CVE-2019-10643CRITICALCVSS 9.8v4.7.02019-04-17
CVE-2019-10643 [CRITICAL] CWE-287 CVE-2019-10643: Contao 4.7 allows Use of a Key Past its Expiration Date. Contao 4.7 allows Use of a Key Past its Expiration Date.
nvd
CVE-2018-20028MEDIUMCVSS 6.5≥ 3.0.0, < 3.5.37≥ 4.4.0, < 4.4.31+1 more2019-04-17
CVE-2018-20028 [MEDIUM] CVE-2018-20028: Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control. Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
nvd
CVE-2017-10993HIGHCVSS 8.8≤ 3.5.27v4.0.0+26 more2017-07-21
CVE-2017-10993 [HIGH] CWE-22 CVE-2017-10993: Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary l Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
nvd
CVE-2015-0269MEDIUMCVSS 4.3≤ 3.2.18v3.4.0+3 more2017-05-26
CVE-2015-0269 [MEDIUM] CWE-22 CVE-2015-0269: Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote auth Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.
nvd
CVE-2012-1297MEDIUMCVSS 6.8PoC≤ 2.11.0v2.0+91 more2012-03-19
CVE-2012-1297 [MEDIUM] CWE-352 CVE-2012-1297: Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a
nvd
CVE-2011-4335MEDIUMCVSS 4.3PoC≤ 2.10.1v2.0+88 more2011-11-28
CVE-2011-4335 [MEDIUM] CWE-79 CVE-2011-4335: Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers t Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action.
nvd
CVE-2011-0508MEDIUMCVSS 4.3v2.9.22011-01-20
CVE-2011-0508 [MEDIUM] CWE-79 CVE-2011-0508: Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2 Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
nvd