Contao Open Source CMS
Menu
Close
Skip navigation
  • Discover
    • Features
    • Case studies
    • News
    • Events
    • Team
    • Online demo
  • Download
    • Download
    • Media
    • Release plan
  • Partners
    • Contao partners
    • Service description
    • Become a partner
  • Support
    • Documentation
    • Report a bug
    • Security advisories
    • Contao network
  • Deutsch
  • English

Pro-Tip: The menu can also be openend and closed with the m key.

Security advisories

Here you will find a list of vulnerabilities that have already been found and fixed in Contao. If you think that you have found a security issue in Contao, please report it according to our security policy.

2026

2026-06-15 16:45 by Leo Feyer

Path traversal in the jobs module

Date: 2026-06-15
CVE ID: CVE-2026-55825

It is theoretically possible to download the log file of another job by using a manipulated download URL.

Security advisory

2026-06-15 16:44 by Leo Feyer

Credentials disclosure in the crawler

Date: 2026-06-15
CVE ID: CVE-2026-55824

If the crawler is set to crawl protected pages, it sends the authorization credentials to externals URLs.

Security advisory

Archive

  • 2026 2 entries
  • 2025 7 entries
  • 2024 8 entries
  • 2023 2 entries
  • 2022 1 entry
  • 2021 4 entries
  • 2020 1 entry
  • 2019 7 entries
  • 2018 4 entries
  • 2017 2 entries
  • 2015 1 entry

Subscribe

  • RSS feed
  • See all options
Skip navigation
  • Sitemap
  • Privacy notice
  • Legal notice