CVE-2026-107842

CVE-2026-107842 published: Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, URLs, and indexed context snippets to unauthenticated visitors when contao.search.index_protected is changed from enabled to disabled....

View full NVD advisory → ← Back to CVE watch