PatchSiren

contao CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Contao CVE published 2026-07-31

CVE-2026-57232

The Contao Feed Reader front-end module is vulnerable to SSRF attacks due to a lack of scheme or private-address validation. A backend user with module-edit permissions can make the server request internal network services, loopback addresses, or cloud metadata endpoints. This issue affects Contao versions from 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8. The vulnerability is fixed in Contao ve [truncated]