contao/core-bundle Security Advisories for 4.13.46 (5)
- 
                        [MEDIUM] Contao discloses sensitive information in the front end search indexPKSA-66g4-yhz3-k3zh CVE-2025-57756 GHSA-2xmj-8wmq-7475 Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0-RC1,<5.3.38|>=4.9.14,<4.13.56 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploadsPKSA-pmyp-m45j-62p1 CVE-2025-29790 GHSA-vqqr-fgmh-f626 Affected version: >=5.4.0,<5.5.6|>=5.3.0,<5.3.30|>=4.0.0,<4.13.54 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao affected by insert tag injection via canonical URLPKSA-8psg-sb44-9n6y CVE-2024-45612 GHSA-2xpq-xp6c-5mgj Affected version: >=5.4.0,<5.4.3|>=5.0.0,<5.3.15|>=4.13.0,<4.13.49 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao affected by directory traversal in the file selector widgetPKSA-gkh9-zxxg-dpvd CVE-2024-45604 GHSA-4p75-5p53-65m9 Affected version: <4.13.49 Reported by: 
 GitHub
- 
                        [HIGH] Contao affected by remote command execution through file uploadPKSA-5k7g-byhd-8xrm CVE-2024-45398 GHSA-vm6r-j788-hjh5 Affected version: >=5.4.0,<5.4.3|>=5.0.0,<5.3.15|>=4.0.0,<4.13.49 Reported by: 
 GitHub