← Vulnerability feed

Vulnerability record · CVE-2019-19745 · published 17 December 2019

CVE-2019-19745: Contao unrestricted file upload vulnerability

Contao · Contao

Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.

8.8 CVSS 3.1 High EPSS 1.1% · top 35.5% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19745 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26265Contao os command injection vulnerabilityContao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.EPSS 30%9.8CVE-2019-11512Contao sql injection vulnerabilityContao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.EPSS 1.5%8.8CVE-2024-45398Contao unrestricted file upload vulnerabilityContao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the…EPSS 0.53%8.8CVE-2012-4383Contao sql injection vulnerabilitycontao prior to 2.11.4 has a sql injection vulnerabilityEPSS 0.92%7.2CVE-2021-37626Contao code injection vulnerabilityContao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …EPSS 1.3%7.2CVE-2021-37627Contao improper privilege management vulnerabilityContao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r…EPSS 1.0%7.1CVE-2024-30262Contao insufficient session expiration vulnerabilityContao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or t…EPSS 0.50%6.6CVE-2025-65960Contao vulnerabilityContao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the con…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2019-19745), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.