CVE-2014-1860: Contao CMS

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

Affected products

  • Contao Contao CMS: up to and including 3.2.4

Published 2020-01-08. Last modified 2026-06-17.