CVE-2019-19745: Contao
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
Affected products
- Contao Contao: from 4.4, up to and including 4.4.45; from 4.8, up to and including 4.8.5; version 4.0 only; version 4.1 only; version 4.2 only; version 4.3 only; …
Published 2019-12-17. Last modified 2026-06-17.