contao/core-bundle Security Advisories for 5.3.21 (5)
- 
                        [MEDIUM] Contao does not properly manage privileges for page and article fieldsPKSA-4m99-84h8-dntz CVE-2025-57759 GHSA-qqfq-7cpp-hcqj Affected version: >=5.4.0-RC1,<5.6.1|>=5.3.0,<5.3.38 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao can disclose sensitive information in the news modulePKSA-v6p5-ssqr-1zcw CVE-2025-57757 GHSA-w53m-gxvg-vx7p Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0-RC1,<5.3.38 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao discloses sensitive information in the front end search indexPKSA-66g4-yhz3-k3zh CVE-2025-57756 GHSA-2xmj-8wmq-7475 Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0-RC1,<5.3.38|>=4.9.14,<4.13.56 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao applies improper access control in the back end votersPKSA-c2g8-xqxr-4cjw CVE-2025-57758 GHSA-7m47-r75r-cx8v Affected version: >=5.4.0-RC1,<5.6.1|>=5.0.0,<5.3.38 Reported by: 
 GitHub
- 
                        [MEDIUM] Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploadsPKSA-pmyp-m45j-62p1 CVE-2025-29790 GHSA-vqqr-fgmh-f626 Affected version: >=5.4.0,<5.5.6|>=5.3.0,<5.3.30|>=4.0.0,<4.13.54 Reported by: 
 GitHub