CVE-2026-107844 | Contao up to 5.3.49/5.7.11 Image ImagesController Path::join path path traversal
A vulnerability was found in Contao up to 5.3.49/5.7.11. It has been declared as problematic. This issue affects the function Path::join of the file ImagesController of the component Image Handler. Executing a manipulation of the argument path can lead to path traversal.
This vulnerability is tracked as CVE-2026-107844. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More