Impact
ModuleSearch in Contao CMS can reveal protected page titles, URLs, and indexed snippets to any visitor after the contao.search.index_protected setting is switched from enabled to disabled. The flaw does not allow bypassing page protection; it only exposes search metadata and indexed text. The vulnerability is a classic information‑disclosure weakness (CWE‑200).
Affected Systems
Contao CMS implementations from version 4.0.0 up through 5.3.50 and 5.7.12 are affected. The vulnerability was fixed in releases 5.3.50 and 5.7.12, so systems running those or later versions are no longer vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The exploit does not require authentication and can be performed by any anonymous user once the configuration change is made, but there is no evidence of active exploit traffic or inclusion in the CISA KEV catalog. Because the EPSS score is not reported, the likelihood of exploitation cannot be quantified; nevertheless, the disclosure risk is real for sites exposing sensitive page titles or content.
OpenCVE Enrichment
Github GHSA