Here you will find a list of vulnerabilities that have already been found and fixed in Contao. If you think that you have found a security issue in Contao, please report it according to our security policy.
Directory traversal in the back end
by Leo Feyer
CVE ID: CVE-2015-0269
Arnaud Buchoux with Orange Consulting has discovered a directory traversal vulnerability, which allows logged in back end users to view files outside their file mounts or the document root. It is, however, not possible to edit these files or to view their content.
Contao 3.* up to 3.4.3
Update to Contao 3.4.4.