CVE-2019-10641: Contao CMS

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

Affected products

  • Contao Contao CMS: before 3.5.39 (fixed in 3.5.39); from 4.0.0, before 4.7.3 (fixed in 4.7.3)

Published 2019-04-17. Last modified 2026-06-17.