
contao/core-bundle
packagist · Contao Open Source CMS · Repository · Package
Security Advisories for contao/core-bundle in packagist
Moderate
about 1 month ago
Contao does not properly manage privileges for page and article fields
packagist
contao/contao, contao/core-bundle
Moderate
about 1 month ago
Contao can disclose sensitive information in the news module
packagist
contao/contao, contao/core-bundle
Moderate
about 1 month ago
Contao discloses sensitive information in the front end search index
packagist
contao/contao, contao/core-bundle
Moderate
about 1 month ago
Contao applies improper access control in the back end voters
packagist
contao/contao, contao/core-bundle
Moderate
7 months ago
Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads
packagist
contao/core-bundle
Moderate
about 1 year ago
Contao affected by insert tag injection via canonical URL
packagist
contao/core-bundle
Moderate
about 1 year ago
Contao affected by directory traversal in the file selector widget
packagist
contao/core-bundle
High
about 1 year ago
Contao affected by remote command execution through file upload
packagist
contao/core-bundle
Moderate
over 1 year ago
Contao: Cross site scripting in the file manager
packagist
contao/core-bundle
Moderate
over 1 year ago
Contao: Remember-me tokens will not be cleared after a password change
packagist
contao/core-bundle
High
over 1 year ago
Contao: Possible cookie sharing with external domains while checking protected pages for broken links
packagist
contao/core-bundle
Critical
over 3 years ago
Contao SQL injection in the file manager
packagist
contao/core-bundle, contao/contao
Critical
over 3 years ago
Contao SQL injection in the backend and listing module
packagist
contao/listing-bundle, contao/core-bundle, contao/contao
High
over 3 years ago
Cross site scripting via canonical tag in Contao
packagist
contao/contao, contao/core-bundle
Critical
over 3 years ago
Contao Does Not Invalidate Existing Sessions When Password Changes
packagist
contao/core, contao/core-bundle, contao/contao
High
over 3 years ago
Contao Core directory traversal vulnerability
packagist
contao/core, contao/core-bundle, contao/contao
Critical
over 3 years ago
Contao Does Not Expire Tokens Correctly
packagist
contao/core-bundle, contao/contao
Moderate
over 3 years ago
Cross-site Scripting in Contao
packagist
contao/core-bundle, contao/core, contao/contao
Moderate
about 4 years ago
Cross site scripting via HTML attributes in the back end
packagist
contao/core-bundle, contao/contao
High
about 4 years ago
Privilege escalation via form generator
packagist
contao/contao, contao/core-bundle
Moderate
about 4 years ago
PHP file inclusion via insert tags
packagist
contao/contao, contao/core-bundle
Moderate
over 4 years ago
Cross site scripting in the system log
packagist
contao/contao, contao/core-bundle
Moderate
almost 6 years ago
Insert tag injection in the Contao login module
packagist
contao/core-bundle
Moderate
almost 6 years ago
Information disclosure in the Contao backend
packagist
contao/core-bundle
High
almost 6 years ago
Unrestricted file uploads in Contao
packagist
contao/contao, contao/core-bundle