CVE-2017-16558: Contao CMS

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

Affected products

  • Contao Contao CMS: from 3.0.0, up to and including 3.5.30; from 4.0.0, up to and including 4.4.7

Published 2019-04-25. Last modified 2026-06-17.