Contao Open Source CMS
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-65961 contao/core-bundle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.13.57, 5.0.0-RC1 - 5.3.42 and 5.4.0-RC1 - 5.6.5. | 4.0.0 - 4.13.575.0.0-RC1 - 5.3.425.4.0-RC1 - 5.6.5 | Low |
CVE-2025-65960 contao/core-bundle is vulnerable to Insufficient Type Distinction in versions 4.0.0 - 4.13.57, 5.0.0-RC1 - 5.3.42 and 5.4.0-RC1 - 5.6.5. | 4.0.0 - 4.13.575.0.0-RC1 - 5.3.425.4.0-RC1 - 5.6.5 | Medium |
CVE-2025-57759 contao/core-bundle is vulnerable to Improper Privilege Management in versions 5.3.0 - 5.3.38 and 5.4.0-RC1 - 5.6.1. | 5.3.0 - 5.3.385.4.0-RC1 - 5.6.1 | Medium |
CVE-2025-57758 contao/core-bundle is vulnerable to Improper Access Control in versions 5.0.0 - 5.3.38 and 5.4.0-RC1 - 5.6.1. | 5.0.0 - 5.3.385.4.0-RC1 - 5.6.1 | Medium |
CVE-2025-57757 contao/core-bundle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0-RC1 - 5.3.38 and 5.4.0-RC1 - 5.6.1. | 5.0.0-RC1 - 5.3.385.4.0-RC1 - 5.6.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || 2.0 || ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
twig/twig Version ^3.21 | — | — |
cmsig/seal Version ^0.12.2 | — | — |
nyholm/psr7 Version ^1.2 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant