Vulnerabilities (CVE)

Filtered by vendor Contao Subscribe
Filtered by product Contao Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-10993 1 Contao 1 Contao Cms 2019-10-03 6.5 MEDIUM 8.8 HIGH
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
CVE-2019-10642 1 Contao 1 Contao Cms 2019-04-18 6.8 MEDIUM 8.8 HIGH
Contao 4.7 allows CSRF.