CVE-2026-107844

CVE-2026-107844 published: Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical...

View full NVD advisory → ← Back to CVE watch