PT-2025-35102 · Contao · Contao

Fritzmg

·

Published

2025-08-28

·

Updated

2025-08-28

·

CVE-2025-57756

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Contao versions prior to 4.13.56 Contao versions prior to 5.3.38 Contao versions prior to 5.6.1 Contao versions starting from 4.9.14 through 5.6.1
Description: Protected content elements rendered as fragments are indexed and become publicly available in the front end search.
Recommendations: Update to Contao version 4.13.56. Update to Contao version 5.3.38. Update to Contao version 5.6.1. Disable the front end search.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57756
GHSA-2XMJ-8WMQ-7475

Affected Products

Contao