CVE-2025-57756

Source
https://cve.org/CVERecord?id=CVE-2025-57756
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57756.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57756
Aliases
Published
2025-08-28T16:31:40.295Z
Modified
2026-04-10T05:31:09.596264Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Contao discloses sensitive information in the front end search index
Details

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A workaround involves disabling the front end search.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57756.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-612"
    ]
}
References

Affected packages

Git / github.com/contao/contao

Affected ranges

Type
GIT
Repo
https://github.com/contao/contao
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.9.14"
        },
        {
            "fixed": "4.13.56"
        }
    ]
}
Type
GIT
Repo
https://github.com/contao/contao
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.0.0-RC1"
        },
        {
            "fixed": "5.3.38"
        }
    ]
}
Type
GIT
Repo
https://github.com/contao/contao
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.4.0-RC1"
        },
        {
            "fixed": "5.6.1"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57756.json"