PT-2025-35105 · Contao · Contao

Lukasbableck

·

Published

2025-08-28

·

Updated

2025-08-28

·

CVE-2025-57759

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Contao versions 5.3.0 through 5.3.37 Contao versions 5.6.0
Description: Contao is an Open Source CMS. Back end users may be able to edit fields of pages and articles without the necessary permissions under certain conditions.
Recommendations: Update to Contao version 5.3.38. Update to Contao version 5.6.1.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-57759
GHSA-QQFQ-7CPP-HCQJ

Affected Products

Contao