Contao is a modestly represented content-management system whose vulnerability footprint, while narrow in product scope, commands attention within the top decile of the landscape due to the system's broad deployment in web publishing and site administration. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and a moderate tendency to acquire public exploit code. The exposure recurs consistently through web-application input-handling weakness classes—cross-site scripting, path traversal, injection flaws, and SQL injection—alongside information-disclosure risks, reflecting the parsing and database-access patterns inherent to a templating and content-delivery platform. Defenders should prioritize Contao updates as part of routine CMS patch cycles and apply input-validation and output-encoding discipline to custom extensions; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Contao over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26265CRITICAL Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter. | Mar 18, 2022 | 9.8 | 47 | NO | NO |
CVE-2022-24899MEDIUM Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject c | May 6, 2022 | 6.1 | 33 | NO | YES |
CVE-2012-1297MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of admi | Mar 19, 2012 | 6.8 | 32 | NO | YES |
CVE-2019-11512CRITICAL Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. | Jul 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-16558CRITICAL Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module. | Apr 25, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-10643CRITICAL Contao 4.7 allows Use of a Key Past its Expiration Date. | Apr 17, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-10641CRITICAL Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password. | Apr 17, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-10642HIGH Contao 4.7 allows CSRF. | Apr 17, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-10993HIGH Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal. | Jul 21, 2017 | 8.8 | 28 | NO | NO |
CVE-2012-4383HIGH contao prior to 2.11.4 has a sql injection vulnerability | Jan 29, 2020 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Contao.
Media articles that mention a CVE ID that affects a product developed by Contao — matched by CVE ID, not by vendor name.