Protected content elements that are rendered as fragments are indexed and become publicly available in the front end search.
Update to Contao 4.13.56, 5.3.38 or 5.6.1.
Disable the front end search.
If you have any questions or comments about this advisory, open an issue in contao/contao.
{ "nvd_published_at": "2025-08-28T17:15:36Z", "github_reviewed": true, "github_reviewed_at": "2025-08-28T14:57:45Z", "severity": "MODERATE", "cwe_ids": [ "CWE-200", "CWE-612" ] }