Перейти к содержимому
Noroxi

Записи contao

43 опубликованных записей вендора contao.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
88,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

43 записей
  • CVE-2022-26265
    48В плане

    Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

    КритическаяCVSS 9,8Proof of conceptEPSS 30 %

    contao · contao18 мар. 2022 г.

  • CVE-2014-1860
    40В плане

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    contao · contao cms8 янв. 2020 г.

  • CVE-2017-16558
    39Наблюдать

    Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    contao · contao cms25 апр. 2019 г.

  • CVE-2019-11512
    39Наблюдать

    Contao 4.x allows SQL Injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    contao · contao9 июл. 2019 г.

  • CVE-2019-10641
    39Наблюдать

    Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    contao · contao cms17 апр. 2019 г.

  • CVE-2019-10643
    39Наблюдать

    Contao 4.7 allows Use of a Key Past its Expiration Date.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    contao · contao cms17 апр. 2019 г.

  • CVE-2017-10993
    36Наблюдать

    Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    contao · contao cms21 июл. 2017 г.

  • CVE-2019-19745
    35Наблюдать

    Contao 4.0 through 4.8.5 allows PHP local file inclusion.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    contao · contao17 дек. 2019 г.

  • CVE-2012-4383
    35Наблюдать

    contao prior to 2.11.4 has a sql injection vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    contao · contao29 янв. 2020 г.

  • CVE-2024-45398
    35Наблюдать

    Remote command execution through file upload in contao/core-bundle

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    contao · contao17 сент. 2024 г.

  • CVE-2019-10642
    35Наблюдать

    Contao 4.7 allows CSRF.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    contao · contao cms17 апр. 2019 г.

  • CVE-2021-37626
    28Наблюдать

    PHP file inclusion via insert tags

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    contao · contao11 авг. 2021 г.

  • CVE-2021-37627
    28Наблюдать

    Privilege escalation via form generator

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    contao · contao11 авг. 2021 г.

  • CVE-2024-30262
    28Наблюдать

    Contao's remember-me tokens will not be cleared after a password change

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    contao · contao9 апр. 2024 г.

  • CVE-2012-1297
    27Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attack

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    contao · contao cms19 мар. 2012 г.

  • CVE-2018-20028
    26Наблюдать

    Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    contao · contao cms17 апр. 2019 г.

  • CVE-2023-29200
    26Наблюдать

    contao/core-bundle has path traversal vulnerability in the file manager

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    contao · contao25 апр. 2023 г.

  • CVE-2024-28235
    26Наблюдать

    Contao possible cookie sharing with external domains while checking protected pages for broken links

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    contao · contao9 апр. 2024 г.

  • CVE-2025-65960
    26Наблюдать

    Contao is vulnerable to remote code execution in template closures

    СредняяCVSS 6,6Эксплойта нетEPSS 0 %

    contao · contao25 нояб. 2025 г.

  • CVE-2022-24899
    25Наблюдать

    Cross site scripting via canonical tag

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    contao · contao5 мая 2022 г.

  • CVE-2018-10125
    24Наблюдать

    Contao before 4.5.7 has XSS in the system log.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    contao · contao16 мар. 2020 г.

  • CVE-2021-35210
    24Наблюдать

    Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    contao · contao23 июн. 2021 г.

  • CVE-2018-5478
    24Наблюдать

    Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    contao · contao21 сент. 2023 г.

  • CVE-2019-19712
    21Наблюдать

    Contao 4.0 through 4.8.5 has Insecure Permissions.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    contao · contao17 дек. 2019 г.

  • CVE-2019-19714
    21Наблюдать

    Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    contao · contao17 дек. 2019 г.