CVE-2019-10641: Contao CMS
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Affected products
- Contao Contao CMS: before 3.5.39 (fixed in 3.5.39); from 4.0.0, before 4.7.3 (fixed in 4.7.3)
Published 2019-04-17. Last modified 2026-06-17.