CVE-2026-107848

CVE-2026-107848 published: Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the...

View full NVD advisory → ← Back to CVE watch