contao/core Security Advisories for 3.5.31 (3)
- 
                        [CRITICAL] Existing sessions are not correctly invalidated when a user changes their passwordPKSA-fcyb-3n6p-v7sp CVE-2019-10641 GHSA-vcgg-hp4r-87gx Affected version: >=3.0.0,<3.5.39 Reported by: 
 FriendsOfPHP/security-advisories, GitHub
- 
                        [MEDIUM] Cross-site scripting (XSS) vulnerability in the system log of the back endPKSA-ftwh-331g-zg9s CVE-2018-10125 GHSA-pj4j-287j-f742 Affected version: >=3.0.0,<3.5.35 Reported by: 
 FriendsOfPHP/security-advisories, GitHub
- 
                        [MEDIUM] XSS vulnerabililty in the front end "unsubscribe" module of the newsletter extensionPKSA-ypy6-knh4-dm44 CVE-2018-5478 GHSA-mpg7-2rx9-h5qp Affected version: >=3.0.0,<3.5.32 Reported by: 
 FriendsOfPHP/security-advisories, GitHub