{"id":"CVE-2025-57757","summary":"Contao discloses information in the news module","details":"Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page.","aliases":["GHSA-w53m-gxvg-vx7p"],"modified":"2026-08-12T03:51:46.212884575Z","published":"2025-08-28T16:32:03.487Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-212"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57757.json"},"references":[{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/information-disclosure-in-the-news-module"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57757.json"},{"type":"ADVISORY","url":"https://github.com/contao/contao/security/advisories/GHSA-w53m-gxvg-vx7p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57757"},{"type":"FIX","url":"https://github.com/contao/contao/commit/e75f46b11974fbf7a4652e65c19ad6ca84c59271"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/contao/contao","events":[{"introduced":"de632fca83b601bd8496058e3f8a8e874ad8c341"},{"fixed":"be50a928909e6b8d27eac26274594a0b1a28d15c"},{"introduced":"3173ec39227e5454439be24f7169bad5e0eb69f8"},{"fixed":"b9d86dfd3af4b5ee9b2a0f1d3340197cebeb3052"},{"fixed":"e75f46b11974fbf7a4652e65c19ad6ca84c59271"}],"database_specific":{"extracted_events":[{"introduced":"5.3.0"},{"fixed":"5.3.38"},{"introduced":"5.4.0"},{"fixed":"5.6.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*"}}],"versions":["5.3.37","5.3.36","5.3.35","5.3.34","5.3.33","5.3.32","5.3.31","5.3.30","5.3.29","5.3.28","5.3.27","5.3.26","5.3.25","5.3.24","5.3.23","5.3.22","5.3.21","5.3.20","5.3.19","5.3.18","5.3.17","5.3.16","5.3.15","5.3.14","5.3.13","5.3.12","5.3.11","5.3.10","5.3.9","5.3.8","5.3.7","5.3.6","5.3.5","5.3.4","5.3.3","5.3.2","5.3.1","5.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57757.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}