Leo Feyer
11 exploits
Active since Apr 2023
Contao 4.0.0-4.13.39 - Stored Cross-Site Scripting via Filename Upload
CVSS 5.4
Contao 4.0.0-4.13.39 - Insert Tag Injection via Form Generator
CVSS 3.1
Contao 2.0.0-4.13.39 and 5.0.0-5.3.3 - CSS Injection via BBCode in Comments
CVSS 4.3
Contao 4.9.0-4.13.39 - Session Cookie Disclosure via Crawler External URL Requests
CVSS 8.3
Contao <4.9.40, <4.13.21, <5.1.4 - Info Disclosure
CVSS 4.3
Contao 4.0.0-4.13.39 - Stored Cross-Site Scripting via Filename Upload
CVSS 5.4
Contao 4.0.0-4.13.39 - Insert Tag Injection via Form Generator
CVSS 3.1
Contao 2.0.0-4.13.39 and 5.0.0-5.3.3 - CSS Injection via BBCode in Comments
CVSS 4.3
Contao 4.9.0-4.13.39 - Session Cookie Disclosure via Crawler External URL Requests
CVSS 8.3
Contao < 4.13.40 - Insufficient Session Expiration via Remember-Me Tokens
CVSS 5.9
Contao 5.0.0-5.3.37 - Improper Access Control in Back-End Table Access Voter
CVSS 4.3