CVE-2015-0269: Contao CMS
Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.
Affected products
- Contao Contao CMS: up to and including 3.2.18; version 3.4.0 only; version 3.4.1 only; version 3.4.2 only; version 3.4.3 only
Published 2017-05-26. Last modified 2026-06-17.