contao kayıtları
contao üreticisine ait 43 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %88,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
43 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2022-26265Kavram kanıtı | Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.contao · contao · CWE-78 | Kritik9,8 | — | %30,4 | 18 Mar 2022 |
40Planlayın | CVE-2014-1860İstismar yok | Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilitiescontao · contao cms · CWE-502 | Kritik9,8 | — | %3,6 | 8 Oca 2020 |
39İzleyin | CVE-2017-16558İstismar yok | Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.contao · contao cms · CWE-89 | Kritik9,8 | — | %1,5 | 25 Nis 2019 |
39İzleyin | CVE-2019-11512İstismar yok | Contao 4.x allows SQL Injection.contao · contao · CWE-89 | Kritik9,8 | — | %1,5 | 9 Tem 2019 |
39İzleyin | CVE-2019-10641İstismar yok | Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.contao · contao cms · CWE-640 | Kritik9,8 | — | %1,3 | 17 Nis 2019 |
39İzleyin | CVE-2019-10643İstismar yok | Contao 4.7 allows Use of a Key Past its Expiration Date.contao · contao cms · CWE-287 | Kritik9,8 | — | %1,3 | 17 Nis 2019 |
36İzleyin | CVE-2017-10993İstismar yok | Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter icontao · contao cms · CWE-22 | Yüksek8,8 | — | %2,7 | 21 Tem 2017 |
35İzleyin | CVE-2019-19745İstismar yok | Contao 4.0 through 4.8.5 allows PHP local file inclusion.contao · contao · CWE-434 | Yüksek8,8 | — | %1,1 | 17 Ara 2019 |
35İzleyin | CVE-2012-4383İstismar yok | contao prior to 2.11.4 has a sql injection vulnerabilitycontao · contao · CWE-89 | Yüksek8,8 | — | %0,9 | 29 Oca 2020 |
35İzleyin | CVE-2024-45398İstismar yok | Remote command execution through file upload in contao/core-bundlecontao · contao · CWE-434 | Yüksek8,8 | — | %0,5 | 17 Eyl 2024 |
35İzleyin | CVE-2019-10642İstismar yok | Contao 4.7 allows CSRF.contao · contao cms · CWE-352 | Yüksek8,8 | — | %0,5 | 17 Nis 2019 |
28İzleyin | CVE-2021-37626İstismar yok | PHP file inclusion via insert tagscontao · contao · CWE-94 | Yüksek7,2 | — | %1,3 | 11 Ağu 2021 |
28İzleyin | CVE-2021-37627İstismar yok | Privilege escalation via form generatorcontao · contao · CWE-269 | Yüksek7,2 | — | %1,0 | 11 Ağu 2021 |
28İzleyin | CVE-2024-30262İstismar yok | Contao's remember-me tokens will not be cleared after a password changecontao · contao · CWE-384 | Yüksek7,1 | — | %0,5 | 9 Nis 2024 |
27İzleyin | CVE-2012-1297Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackcontao · contao cms · CWE-352 | Orta6,8 | — | %1,1 | 19 Mar 2012 |
26İzleyin | CVE-2018-20028İstismar yok | Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.contao · contao cms | Orta6,5 | — | %0,9 | 17 Nis 2019 |
26İzleyin | CVE-2023-29200İstismar yok | contao/core-bundle has path traversal vulnerability in the file managercontao · contao · CWE-22 | Orta6,5 | — | %0,8 | 25 Nis 2023 |
26İzleyin | CVE-2024-28235İstismar yok | Contao possible cookie sharing with external domains while checking protected pages for broken linkscontao · contao · CWE-200 | Orta6,5 | — | %0,7 | 9 Nis 2024 |
26İzleyin | CVE-2025-65960İstismar yok | Contao is vulnerable to remote code execution in template closurescontao · contao · CWE-351 | Orta6,6 | — | %0,2 | 25 Kas 2025 |
25İzleyin | CVE-2022-24899Kavram kanıtı | Cross site scripting via canonical tagcontao · contao · CWE-79 | Orta6,1 | — | %4,5 | 5 May 2022 |
24İzleyin | CVE-2018-10125İstismar yok | Contao before 4.5.7 has XSS in the system log.contao · contao · CWE-79 | Orta6,1 | — | %0,8 | 16 Mar 2020 |
24İzleyin | CVE-2021-35210İstismar yok | Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS.contao · contao · CWE-79 | Orta6,1 | — | %0,7 | 23 Haz 2021 |
24İzleyin | CVE-2018-5478İstismar yok | Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.contao · contao · CWE-79 | Orta6,1 | — | %0,4 | 21 Eyl 2023 |
21İzleyin | CVE-2019-19712İstismar yok | Contao 4.0 through 4.8.5 has Insecure Permissions.contao · contao · CWE-276 | Orta5,3 | — | %0,9 | 17 Ara 2019 |
21İzleyin | CVE-2019-19714İstismar yok | Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output.contao · contao · CWE-116 | Orta5,3 | — | %0,8 | 17 Ara 2019 |
- CVE-2022-2626548Planlayın
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %30contao · contao18 Mar 2022
- CVE-2014-186040Planlayın
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4contao · contao cms8 Oca 2020
- CVE-2017-1655839İzleyin
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
KritikCVSS 9,8İstismar yokEPSS %2contao · contao cms25 Nis 2019
- CVE-2019-1151239İzleyin
Contao 4.x allows SQL Injection.
KritikCVSS 9,8İstismar yokEPSS %1contao · contao9 Tem 2019
- CVE-2019-1064139İzleyin
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
KritikCVSS 9,8İstismar yokEPSS %1contao · contao cms17 Nis 2019
- CVE-2019-1064339İzleyin
Contao 4.7 allows Use of a Key Past its Expiration Date.
KritikCVSS 9,8İstismar yokEPSS %1contao · contao cms17 Nis 2019
- CVE-2017-1099336İzleyin
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter i
YüksekCVSS 8,8İstismar yokEPSS %3contao · contao cms21 Tem 2017
- CVE-2019-1974535İzleyin
Contao 4.0 through 4.8.5 allows PHP local file inclusion.
YüksekCVSS 8,8İstismar yokEPSS %1contao · contao17 Ara 2019
- CVE-2012-438335İzleyin
contao prior to 2.11.4 has a sql injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1contao · contao29 Oca 2020
- CVE-2024-4539835İzleyin
Remote command execution through file upload in contao/core-bundle
YüksekCVSS 8,8İstismar yokEPSS %1contao · contao17 Eyl 2024
- CVE-2019-1064235İzleyin
Contao 4.7 allows CSRF.
YüksekCVSS 8,8İstismar yokEPSS %0contao · contao cms17 Nis 2019
- CVE-2021-3762628İzleyin
PHP file inclusion via insert tags
YüksekCVSS 7,2İstismar yokEPSS %1contao · contao11 Ağu 2021
- CVE-2021-3762728İzleyin
Privilege escalation via form generator
YüksekCVSS 7,2İstismar yokEPSS %1contao · contao11 Ağu 2021
- CVE-2024-3026228İzleyin
Contao's remember-me tokens will not be cleared after a password change
YüksekCVSS 7,1İstismar yokEPSS %0contao · contao9 Nis 2024
- CVE-2012-129727İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attack
OrtaCVSS 6,8Kavram kanıtıEPSS %1contao · contao cms19 Mar 2012
- CVE-2018-2002826İzleyin
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
OrtaCVSS 6,5İstismar yokEPSS %1contao · contao cms17 Nis 2019
- CVE-2023-2920026İzleyin
contao/core-bundle has path traversal vulnerability in the file manager
OrtaCVSS 6,5İstismar yokEPSS %1contao · contao25 Nis 2023
- CVE-2024-2823526İzleyin
Contao possible cookie sharing with external domains while checking protected pages for broken links
OrtaCVSS 6,5İstismar yokEPSS %1contao · contao9 Nis 2024
- CVE-2025-6596026İzleyin
Contao is vulnerable to remote code execution in template closures
OrtaCVSS 6,6İstismar yokEPSS %0contao · contao25 Kas 2025
- CVE-2022-2489925İzleyin
Cross site scripting via canonical tag
OrtaCVSS 6,1Kavram kanıtıEPSS %4contao · contao5 May 2022
- CVE-2018-1012524İzleyin
Contao before 4.5.7 has XSS in the system log.
OrtaCVSS 6,1İstismar yokEPSS %1contao · contao16 Mar 2020
- CVE-2021-3521024İzleyin
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS.
OrtaCVSS 6,1İstismar yokEPSS %1contao · contao23 Haz 2021
- CVE-2018-547824İzleyin
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
OrtaCVSS 6,1İstismar yokEPSS %0contao · contao21 Eyl 2023
- CVE-2019-1971221İzleyin
Contao 4.0 through 4.8.5 has Insecure Permissions.
OrtaCVSS 5,3İstismar yokEPSS %1contao · contao17 Ara 2019
- CVE-2019-1971421İzleyin
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output.
OrtaCVSS 5,3İstismar yokEPSS %1contao · contao17 Ara 2019