Security is a top priority for Contao. Please help us make the system more secure!
If you think that you have found a security issue in Contao, please open a security advisory on GitHub.
Never disclose any information about a vulnerability on the public web (blog posts, tweets, GitHub issues, etc.) before the vulnerability has been acknowledged and fixed in a new Contao version!
For every report, we first attempt to confirm the vulnerability. When it is confirmed, the core team works on a solution following these steps:
- Acknowledge the security advisory;
- Work on a patch;
- Obtain a CVE identifier;
- Publish a security announcement on contao.org;
- Ask the reporter to review the patch pull request;
- Apply the patch to all maintained versions of Contao;
- Release new versions for all affected versions;
- Announce the new versions and the vulnerability on contao.org;
Contao is an open-source project where most of the work is done by volunteers. We appreciate that developers are trying to find security issues in Contao and report them responsibly, but we are currently unable to pay bug bounties.
Check the security advisories for a list of all security vulnerabilities that were already found and fixed in Contao.