Contao news

Read the official Contao announcements.

Contao 4.4.1 is available

by Leo Feyer – Announcements

Contao version 4.4.1 is available. The bugfix release fixes an arbitrary PHP file inclusion vulnerability in the back end (CVE-2017-10993).


A logged in back end user can include arbitrary PHP files by manipulating an URL parameter. Since Contao does not allow to upload PHP files in the file manager, the attack is limited to the existing PHP files on the server.

The issue affects Contao 3.0.0 to 3.5.27 and Contao 4.0.0 to 4.4.0.

Although we do not consider the vulnerability to be critical, we strongly recommend to update to either Contao 3.5.28 or Contao 4.4.1.

DCA picker

Unfortunately, the new DCA picker, which has been added in Contao 4.4.0, is still not usable for regular back end users in Contao 4.4.1.

To fix the picker, we have to rework the implementation from scratch (see contao/core-bundle#950), therefore we ask all developers not to publish extensions using the new picker yet. The new implementation cannot be backwards compatible for technical reasons.

Also see: GitHub tickets | GitHub compare view | Contao change log | Release overview

Show all news


Add a comment

Please add 4 and 8.