Is Contao 5.2.10 patched?
Current stable (5.7.7): 100/100
5.2.10 has 2 open critical-or-high vulnerabilities. Run 5.3.15 or later to clear them. See what 5.3.15 fixes →
Summary iPlain-English security status for Contao 5.2.10, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Contao 5.2.10 is part of the 5.2 release line. 10 known vulnerabilities affect it. The minimum safe version is 5.3.15 — upgrade to it or later to clear the open critical/high issues. The 5.2 line reached end-of-life on 2024-02-14, so it no longer receives security patches. The latest supported Contao release is 5.7.7.
Known issues affecting 5.2.10
Exploited first, then by exploitation probability.
CVE-2024-28235 HIGH EPSS 1% → fixed in 5.3.4 CVE-2024-28234 MEDIUM EPSS 1% → fixed in 5.3.4 CVE-2024-45398 HIGH EPSS 1% → fixed in 5.4.3 CVE-2024-28190 MEDIUM EPSS 1% → fixed in 5.3.4 CVE-2024-28191 LOW EPSS 0% → fixed in 5.3.4 CVE-2024-45965 MEDIUM EPSS 0% → fixed in 5.5.6 CVE-2025-57756 MEDIUM EPSS 0% → fixed in 5.6.1 CVE-2025-29790 MEDIUM EPSS 0% → fixed in 5.5.6 CVE-2025-65960 MEDIUM EPSS 0% → fixed in 5.6.5 CVE-2025-65961 LOW EPSS 0% → fixed in 5.6.5Other Contao versions
Check another release line of Contao.
Frequently asked
Is Contao 5.2.10 patched?
Contao 5.2.10 is end-of-life and no longer receives security patches. Move to 5.7.7.
What version should I upgrade Contao 5.2.10 to?
Upgrade Contao 5.2.10 to at least 5.3.15 to clear its 2 open critical-or-high vulnerabilities.
When does Contao 5.2 reach end-of-life?
Contao 5.2 reached end-of-life on 2024-02-14 and no longer receives security patches.
What is the latest version of Contao?
The latest supported Contao release is 5.7.7.
Is Contao 5.2.10 still receiving security updates?
No — Contao 5.2.10 is on the 5.2 line, which reached end-of-life on 2024-02-14 and no longer receives security updates. Upgrade to 5.7.7 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Contao's official advisory before you patch or upgrade — Contao official site ↗