Contao Open Source CMS
Menu
Close
Skip navigation
  • Discover
    • Features
    • Case studies
    • News
    • Events
    • Team
    • Online demo
  • Download
    • Download
    • Media
    • Release plan
  • Partners
    • Contao partners
    • Service description
    • Become a partner
  • Support
    • Overview
    • Documentation
    • Report a bug
    • Security advisories
    • Contao network
  • Deutsch
  • English

Pro-Tip: The menu can also be openend and closed with the m key.

Security advisories

Here you will find a list of vulnerabilities that have already been found and fixed in Contao. If you think that you have found a security issue in Contao, please report it according to our security policy.

2017

2017-11-15 08:51 by Leo Feyer

SQL injection in the back end search filter and the listing module

Date: 2017-11-15
CVE ID: CVE-2017-16558

The back end search filter and the listing module are vulnerable to SQL injections. The problem affects all Contao versions as of Contao 4.0 and has been fixed in Contao 4.4.8.

Security advisory

2017-07-12 09:09 by Leo Feyer

PHP file inclusion in the back end

Date: 2017-07-12
CVE ID: CVE-2017-10993

A logged in back end user can include arbitrary existing PHP. The problem affects all Contao versions and has been fixed in Contao 3.5.27 and 4.4.0.

Security advisory

Archive

  • 2025 5 entries
  • 2024 8 entries
  • 2023 2 entries
  • 2022 1 entry
  • 2021 4 entries
  • 2020 1 entry
  • 2019 7 entries
  • 2018 4 entries
  • 2017 2 entries
  • 2015 1 entry

Subscribe

  • RSS feed
  • See all options
Skip navigation
  • Sitemap
  • Privacy notice
  • Legal notice