Vulnerability Description
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao | >= 5.3.0, < 5.3.38 |
Related Weaknesses (CWE)
References
- https://contao.org/en/security-advisories/information-disclosure-in-the-news-modVendor Advisory
- https://github.com/contao/contao/commit/e75f46b11974fbf7a4652e65c19ad6ca84c59271Patch
- https://github.com/contao/contao/security/advisories/GHSA-w53m-gxvg-vx7pPatchThird Party Advisory
FAQ
What is CVE-2025-57757?
CVE-2025-57757 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly avai...
How severe is CVE-2025-57757?
CVE-2025-57757 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57757?
Check the references section above for vendor advisories and patch information. Affected products include: Contao Contao.