İçeriğe atla
Noroxi

contao kayıtları

contao üreticisine ait 43 yayımlanmış kayıt.

Tüm kayıtlar

43 kayıt
  • CVE-2022-26265
    48Planlayın

    Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

    KritikCVSS 9,8Kavram kanıtıEPSS %30

    contao · contao18 Mar 2022

  • CVE-2014-1860
    40Planlayın

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    contao · contao cms8 Oca 2020

  • CVE-2017-16558
    39İzleyin

    Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

    KritikCVSS 9,8İstismar yokEPSS %2

    contao · contao cms25 Nis 2019

  • CVE-2019-11512
    39İzleyin

    Contao 4.x allows SQL Injection.

    KritikCVSS 9,8İstismar yokEPSS %1

    contao · contao9 Tem 2019

  • CVE-2019-10641
    39İzleyin

    Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

    KritikCVSS 9,8İstismar yokEPSS %1

    contao · contao cms17 Nis 2019

  • CVE-2019-10643
    39İzleyin

    Contao 4.7 allows Use of a Key Past its Expiration Date.

    KritikCVSS 9,8İstismar yokEPSS %1

    contao · contao cms17 Nis 2019

  • CVE-2017-10993
    36İzleyin

    Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter i

    YüksekCVSS 8,8İstismar yokEPSS %3

    contao · contao cms21 Tem 2017

  • CVE-2019-19745
    35İzleyin

    Contao 4.0 through 4.8.5 allows PHP local file inclusion.

    YüksekCVSS 8,8İstismar yokEPSS %1

    contao · contao17 Ara 2019

  • CVE-2012-4383
    35İzleyin

    contao prior to 2.11.4 has a sql injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    contao · contao29 Oca 2020

  • CVE-2024-45398
    35İzleyin

    Remote command execution through file upload in contao/core-bundle

    YüksekCVSS 8,8İstismar yokEPSS %1

    contao · contao17 Eyl 2024

  • CVE-2019-10642
    35İzleyin

    Contao 4.7 allows CSRF.

    YüksekCVSS 8,8İstismar yokEPSS %0

    contao · contao cms17 Nis 2019

  • CVE-2021-37626
    28İzleyin

    PHP file inclusion via insert tags

    YüksekCVSS 7,2İstismar yokEPSS %1

    contao · contao11 Ağu 2021

  • CVE-2021-37627
    28İzleyin

    Privilege escalation via form generator

    YüksekCVSS 7,2İstismar yokEPSS %1

    contao · contao11 Ağu 2021

  • CVE-2024-30262
    28İzleyin

    Contao's remember-me tokens will not be cleared after a password change

    YüksekCVSS 7,1İstismar yokEPSS %0

    contao · contao9 Nis 2024

  • CVE-2012-1297
    27İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attack

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    contao · contao cms19 Mar 2012

  • CVE-2018-20028
    26İzleyin

    Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.

    OrtaCVSS 6,5İstismar yokEPSS %1

    contao · contao cms17 Nis 2019

  • CVE-2023-29200
    26İzleyin

    contao/core-bundle has path traversal vulnerability in the file manager

    OrtaCVSS 6,5İstismar yokEPSS %1

    contao · contao25 Nis 2023

  • CVE-2024-28235
    26İzleyin

    Contao possible cookie sharing with external domains while checking protected pages for broken links

    OrtaCVSS 6,5İstismar yokEPSS %1

    contao · contao9 Nis 2024

  • CVE-2025-65960
    26İzleyin

    Contao is vulnerable to remote code execution in template closures

    OrtaCVSS 6,6İstismar yokEPSS %0

    contao · contao25 Kas 2025

  • CVE-2022-24899
    25İzleyin

    Cross site scripting via canonical tag

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    contao · contao5 May 2022

  • CVE-2018-10125
    24İzleyin

    Contao before 4.5.7 has XSS in the system log.

    OrtaCVSS 6,1İstismar yokEPSS %1

    contao · contao16 Mar 2020

  • CVE-2021-35210
    24İzleyin

    Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    contao · contao23 Haz 2021

  • CVE-2018-5478
    24İzleyin

    Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.

    OrtaCVSS 6,1İstismar yokEPSS %0

    contao · contao21 Eyl 2023

  • CVE-2019-19712
    21İzleyin

    Contao 4.0 through 4.8.5 has Insecure Permissions.

    OrtaCVSS 5,3İstismar yokEPSS %1

    contao · contao17 Ara 2019

  • CVE-2019-19714
    21İzleyin

    Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output.

    OrtaCVSS 5,3İstismar yokEPSS %1

    contao · contao17 Ara 2019