contao/contao Security Advisories for 4.13.1 (9)
-
Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)
Affected version: >=4.9.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)
Affected version: >=4.1.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)
Affected version: >=4.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)
Affected version: >=4.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)
Affected version: >=4.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
[LOW] Credentials disclosure in the crawler
PKSA-8pr1-zw9p-tzyx CVE-2026-55824 GHSA-3mr9-p497-58f6
Affected version: >=4.13.0,<5.3.47|>=5.4.0,<5.7.7
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] Contao discloses sensitive information in the front end search index
PKSA-34p6-239r-z7w2 CVE-2025-57756 GHSA-2xmj-8wmq-7475
Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0-RC1,<5.3.38|>=4.9.14,<4.13.56
Reported by:
GitHub -
[HIGH] Directory traversal vulnerability in the file manager
PKSA-3m2g-ygwq-rxnz CVE-2023-29200 GHSA-fp7q-xhhw-6rj3
Affected version: >=4.9.0,<4.9.40|>=4.13.0,<4.13.21|>=5.1.0,<5.1.4
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] Cross site scripting via canonical URL
PKSA-jgdm-q1xh-kwnj CVE-2022-24899 GHSA-m8x6-6r63-qvj2
Affected version: >=4.13.0,<4.13.3
Reported by:
FriendsOfPHP/security-advisories, GitHub