Is Contao 5.1.11 patched?
Current stable (5.7.7): 100/100
5.1.11 has 2 open critical-or-high vulnerabilities. Run 5.3.15 or later to clear them. See what 5.3.15 fixes →
Summary iPlain-English security status for Contao 5.1.11, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Contao 5.1.11 is part of the 5.1 release line. 10 known vulnerabilities affect it. The minimum safe version is 5.3.15 — upgrade to it or later to clear the open critical/high issues. The 5.1 line reached end-of-life on 2023-08-14, so it no longer receives security patches. The latest supported Contao release is 5.7.7.
Known issues affecting 5.1.11
Exploited first, then by exploitation probability.
CVE-2024-28235 HIGH EPSS 1% → fixed in 5.3.4 CVE-2024-28234 MEDIUM EPSS 1% → fixed in 5.3.4 CVE-2024-45398 HIGH EPSS 1% → fixed in 5.4.3 CVE-2024-28190 MEDIUM EPSS 1% → fixed in 5.3.4 CVE-2024-28191 LOW EPSS 0% → fixed in 5.3.4 CVE-2024-45965 MEDIUM EPSS 0% → fixed in 5.5.6 CVE-2025-57756 MEDIUM EPSS 0% → fixed in 5.6.1 CVE-2025-29790 MEDIUM EPSS 0% → fixed in 5.5.6 CVE-2025-65960 MEDIUM EPSS 0% → fixed in 5.6.5 CVE-2025-65961 LOW EPSS 0% → fixed in 5.6.5Other Contao versions
Check another release line of Contao.
Frequently asked
Is Contao 5.1.11 patched?
Contao 5.1.11 is end-of-life and no longer receives security patches. Move to 5.7.7.
What version should I upgrade Contao 5.1.11 to?
Upgrade Contao 5.1.11 to at least 5.3.15 to clear its 2 open critical-or-high vulnerabilities.
When does Contao 5.1 reach end-of-life?
Contao 5.1 reached end-of-life on 2023-08-14 and no longer receives security patches.
What is the latest version of Contao?
The latest supported Contao release is 5.7.7.
Is Contao 5.1.11 still receiving security updates?
No — Contao 5.1.11 is on the 5.1 line, which reached end-of-life on 2023-08-14 and no longer receives security updates. Upgrade to 5.7.7 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Contao's official advisory before you patch or upgrade — Contao official site ↗