Description
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
Remediation
References
Related Vulnerabilities
WordPress Cross-Site Request Forgery (0.70 - 3.6.1)
Craft CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2026-33161)
GlassFish Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3239)
WordPress Plugin Users Ultra Membership Cross-Site Scripting (1.5.78)