Contao Open Source CMS
Menu
Close
Skip navigation
  • Discover
    • Features
    • Case studies
    • News
    • Events
    • Team
    • Online demo
  • Download
    • Download
    • Media
    • Release plan
  • Partners
    • Contao partners
    • Service description
    • Become a partner
  • Support
    • Overview
    • Documentation
    • Report a bug
    • Security advisories
    • Contao network
  • Deutsch
  • English

Pro-Tip: The menu can also be openend and closed with the m key.

Security advisories

Here you will find a list of vulnerabilities that have already been found and fixed in Contao. If you think that you have found a security issue in Contao, please report it according to our security policy.

2020

2020-09-24 10:20 by Leo Feyer

Insert tag injection in forms

Date: 2020-09-24
CVE ID: CVE-2020-25768

It is possible to inject insert tags in front end forms which will be replaced when the page is rendered. The problem affects all Contao versions as of Contao 4.0 and has been fixed in Contao 4.4.52, 4.9.6 and 4.10.1.

Security advisory

Archive

  • 2025 5 entries
  • 2024 8 entries
  • 2023 2 entries
  • 2022 1 entry
  • 2021 4 entries
  • 2020 1 entry
  • 2019 7 entries
  • 2018 4 entries
  • 2017 2 entries
  • 2015 1 entry

Subscribe

  • RSS feed
  • See all options
Skip navigation
  • Sitemap
  • Privacy notice
  • Legal notice