CVE-2025-57757: Contao
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page.
Affected products
- Contao Contao: from 5.3.0, before 5.3.38 (fixed in 5.3.38); from 5.4.0, before 5.6.1 (fixed in 5.6.1)
Published 2025-08-28. Last modified 2026-06-17.