CVE-2025-57756
Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A workaround involves disabling the front end search.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-200, CWE-612
- Published
- 2025-08-28
- Last modified
- 2026-03-13
Affected products
- contao contao
- contao contao
- contao contao
Weakness type
Related vulnerabilities
- CVE-2026-88059 — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-88893 — OpenPanel Unauthenticated Share Lookup Information Disclosure
- CVE-2026-88876 — AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD
- CVE-2026-88874 — AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass
- CVE-2026-0305 — Prisma Access Agent: Information Disclosure Vulnerability on Linux
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets