contao CVE Vulnerabilities & Metrics

Focus on contao vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About contao Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with contao. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total contao CVEs: 32
Earliest CVE date: 20 Jan 2011, 19:00 UTC
Latest CVE date: 17 Sep 2024, 20:15 UTC

Latest CVE reference: CVE-2024-45604

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 8

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 166.67%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 166.67%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical contao CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.9

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 12
4.0-6.9 18
7.0-8.9 5
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS contao CVEs

These are the five CVEs with the highest CVSS scores for contao, sorted by severity first and recency.

All CVEs for contao

CVE-2024-45604 contao vulnerability CVSS: 0 17 Sep 2024, 20:15 UTC

Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.

CVE-2024-45398 contao vulnerability CVSS: 0 17 Sep 2024, 20:15 UTC

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory.

CVE-2024-45612 contao vulnerability CVSS: 0 17 Sep 2024, 19:15 UTC

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.

CVE-2024-30262 contao vulnerability CVSS: 0 09 Apr 2024, 17:16 UTC

Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.

CVE-2024-28235 contao vulnerability CVSS: 0 09 Apr 2024, 16:15 UTC

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.

CVE-2024-28234 contao vulnerability CVSS: 0 09 Apr 2024, 14:15 UTC

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable BBCode for comments.

CVE-2024-28191 contao vulnerability CVSS: 0 09 Apr 2024, 14:15 UTC

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, do not output user data from frontend forms next to each other, always separate them by at least one character.

CVE-2024-28190 contao vulnerability CVSS: 0 09 Apr 2024, 14:15 UTC

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and popups in the back end. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, remove upload fields from frontend forms and disable uploads for untrusted back end users.

CVE-2018-5478 contao vulnerability CVSS: 0 21 Sep 2023, 06:15 UTC

Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.

CVE-2023-36806 contao vulnerability CVSS: 0 25 Jul 2023, 19:15 UTC

Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users.

CVE-2023-29200 contao vulnerability CVSS: 0 25 Apr 2023, 18:15 UTC

Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.

CVE-2022-24899 contao vulnerability CVSS: 4.3 06 May 2022, 00:15 UTC

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

CVE-2022-26265 contao vulnerability CVSS: 7.5 18 Mar 2022, 23:15 UTC

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

CVE-2021-35955 contao vulnerability CVSS: 3.5 12 Aug 2021, 15:15 UTC

Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.

CVE-2021-37627 contao vulnerability CVSS: 6.5 11 Aug 2021, 23:15 UTC

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.

CVE-2021-37626 contao vulnerability CVSS: 6.5 11 Aug 2021, 23:15 UTC

Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you cannot update then disable the login for untrusted back end users.

CVE-2021-35210 contao vulnerability CVSS: 4.3 23 Jun 2021, 11:15 UTC

Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.

CVE-2020-25768 contao vulnerability CVSS: 5.0 07 Oct 2020, 21:15 UTC

Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.

CVE-2018-10125 contao vulnerability CVSS: 4.3 16 Mar 2020, 15:15 UTC

Contao before 4.5.7 has XSS in the system log.

CVE-2012-4383 contao vulnerability CVSS: 6.5 29 Jan 2020, 15:15 UTC

contao prior to 2.11.4 has a sql injection vulnerability

CVE-2014-1860 contao vulnerability CVSS: 7.5 08 Jan 2020, 16:15 UTC

Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

CVE-2019-19745 contao vulnerability CVSS: 6.5 17 Dec 2019, 15:15 UTC

Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.

CVE-2019-19714 contao vulnerability CVSS: 5.0 17 Dec 2019, 15:15 UTC

Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.

CVE-2019-19712 contao vulnerability CVSS: 5.0 17 Dec 2019, 14:15 UTC

Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.

CVE-2019-11512 contao vulnerability CVSS: 7.5 09 Jul 2019, 21:15 UTC

Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.

CVE-2017-16558 contao vulnerability CVSS: 7.5 25 Apr 2019, 17:29 UTC

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

CVE-2019-10643 contao vulnerability CVSS: 7.5 17 Apr 2019, 19:29 UTC

Contao 4.7 allows Use of a Key Past its Expiration Date.

CVE-2019-10642 contao vulnerability CVSS: 6.8 17 Apr 2019, 19:29 UTC

Contao 4.7 allows CSRF.

CVE-2019-10641 contao vulnerability CVSS: 5.0 17 Apr 2019, 19:29 UTC

Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

CVE-2018-20028 contao vulnerability CVSS: 4.0 17 Apr 2019, 19:29 UTC

Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.

CVE-2017-10993 contao vulnerability CVSS: 6.5 21 Jul 2017, 06:29 UTC

Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.

CVE-2015-0269 contao vulnerability CVSS: 4.0 26 May 2017, 17:29 UTC

Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.

CVE-2012-1297 contao vulnerability CVSS: 6.8 19 Mar 2012, 18:55 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.

CVE-2011-4335 contao vulnerability CVSS: 4.3 28 Nov 2011, 11:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action.

CVE-2011-0508 contao vulnerability CVSS: 4.3 20 Jan 2011, 19:00 UTC

Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.