contao/contao Security Advisories for 5.4.4 (6)
-
Server-side request forgery (SSRF) via unvalidated RSS feed URLs
PKSA-55tn-sgd6-9twh CVE-2026-57232
Affected version: >=5.3.35,<5.3.48|>=5.4.0,<5.7.9
Reported by:
FriendsOfPHP/security-advisories -
Credentials disclosure in the crawler
PKSA-8pr1-zw9p-tzyx CVE-2026-55824
Affected version: >=4.13.0,<5.3.47|>=5.4.0,<5.7.7
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] Contao does not properly manage privileges for page and article fields
PKSA-1kdh-bqbn-7nqb CVE-2025-57759 GHSA-qqfq-7cpp-hcqj
Affected version: >=5.4.0-RC1,<5.6.1|>=5.3.0,<5.3.38
Reported by:
GitHub -
[MEDIUM] Contao can disclose sensitive information in the news module
PKSA-kh11-db67-t9zk CVE-2025-57757 GHSA-w53m-gxvg-vx7p
Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0-RC1,<5.3.38
Reported by:
GitHub -
[MEDIUM] Contao discloses sensitive information in the front end search index
PKSA-34p6-239r-z7w2 CVE-2025-57756 GHSA-2xmj-8wmq-7475
Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0-RC1,<5.3.38|>=4.9.14,<4.13.56
Reported by:
GitHub -
[MEDIUM] Contao applies improper access control in the back end voters
PKSA-ptp8-kf5w-97c9 CVE-2025-57758 GHSA-7m47-r75r-cx8v
Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0,<5.3.38
Reported by:
GitHub