CVE-2025-57756
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
28/08/2025
Last modified:
02/09/2025
Description
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A workaround involves disabling the front end search.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | 4.9.0 (including) | 4.9.14 (including) |
| cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | 4.10.0 (including) | 4.13.56 (excluding) |
| cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.3.38 (excluding) |
| cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | 5.4.0 (including) | 5.6.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



