Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Contao

First CVE: Jan 20, 2011Active for: 16 yearsTotal CVEs: 43
34.5
VTI Score
Medium

Contao is a modestly represented content-management system whose vulnerability footprint, while narrow in product scope, commands attention within the top decile of the landscape due to the system's broad deployment in web publishing and site administration. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and a moderate tendency to acquire public exploit code. The exposure recurs consistently through web-application input-handling weakness classes—cross-site scripting, path traversal, injection flaws, and SQL injection—alongside information-disclosure risks, reflecting the parsing and database-access patterns inherent to a templating and content-delivery platform. Defenders should prioritize Contao updates as part of routine CMS patch cycles and apply input-validation and output-encoding discipline to custom extensions; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Contao over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2011
15 years ago
Most Recent CVE
Nov 25, 2025
241 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-26265CRITICAL
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
Mar 18, 20229.847NONO
CVE-2022-24899MEDIUM
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject c
May 6, 20226.133NOYES
CVE-2012-1297MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of admi
Mar 19, 20126.832NOYES
CVE-2019-11512CRITICAL
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
Jul 9, 20199.831NONO
CVE-2017-16558CRITICAL
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
Apr 25, 20199.831NONO
CVE-2019-10643CRITICAL
Contao 4.7 allows Use of a Key Past its Expiration Date.
Apr 17, 20199.831NONO
CVE-2019-10641CRITICAL
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Apr 17, 20199.831NONO
CVE-2019-10642HIGH
Contao 4.7 allows CSRF.
Apr 17, 20198.828NONO
CVE-2017-10993HIGH
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
Jul 21, 20178.828NONO
CVE-2012-4383HIGH
contao prior to 2.11.4 has a sql injection vulnerability
Jan 29, 20208.827NONO
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
67%
19%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (93.0%)
Unknown3 (7.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (90.7%)
High1 (2.3%)
Unknown3 (7.0%)
User Interaction
None28 (65.1%)
Unknown3 (7.0%)
Required12 (27.9%)
Privileges Required
Low17 (39.5%)
High5 (11.6%)
None18 (41.9%)
Unknown3 (7.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.3% of CVEs· 95th percentile
ExploitDB
2 CVEs
4.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Contao.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Contao — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Contao's Products

View all 3 CNAs →

Top CWEs