Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26126 | Contao can disclose sensitive information in the news module |
Github GHSA |
GHSA-w53m-gxvg-vx7p | Contao can disclose sensitive information in the news module |
Tue, 02 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* |
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Vendors & Products |
Contao
Contao contao |
Thu, 28 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page. | |
| Title | Contao discloses information in the news module | |
| Weaknesses | CWE-200 CWE-212 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-28T17:48:36.124Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57757
Updated: 2025-08-28T17:45:43.217Z
Status : Analyzed
Published: 2025-08-28T17:15:36.220
Modified: 2025-09-02T17:38:34.263
Link: CVE-2025-57757
No data.
OpenCVE Enrichment
Updated: 2025-08-28T21:21:40Z
EUVD
Github GHSA