Contao
cpe:2.3:a:contao:contao:*:*:*:*:*:*:*
- >= 4.9.14, <= 4.13.55
- >= 5.3, <= 5.3.37
A vulnerability in Contao CMS versions 4.9.14 prior to 4.13.56, 5.3.38, and 5.6.1 allows protected content elements rendered as fragments to be indexed and publicly accessible through the frontend search. This issue has been addressed in versions 4.13.56, 5.3.38, and 5.6.1. Users can temporarily disable the frontend search as a workaround.
This vulnerability leads to unauthorized information disclosure by allowing protected content elements to be indexed and made publicly available in the frontend search.
Users are advised to update to Contao versions 4.13.56, 5.3.38, or 5.6.1. Instructions for updating can be found in the Contao documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.