CVE-2019-19714: Contao

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.

Affected products

  • Contao Contao: version 4.8.4 only; version 4.8.5 only

Published 2019-12-17. Last modified 2026-06-17.