Contao 5.x — End of Life
ActiveContao 5.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 5.7LTS | Feb 18, 2026 | Feb 14, 2029 | Feb 14, 2030 | 5.7.13 | Active | |
| 5.6 | Aug 18, 2025 | Feb 14, 2026 | Feb 14, 2026 | 5.6.11 | EOL | |
| 5.5 | Feb 18, 2025 | Aug 14, 2025 | Aug 14, 2025 | 5.5.16 | EOL | |
| 5.4 | Aug 15, 2024 | Feb 14, 2025 | Feb 14, 2025 | 5.4.14 | EOL | |
| 5.3LTS | Feb 16, 2024 | Feb 14, 2027 | Feb 14, 2028 | 5.3.51 | Active | |
| 5.2 | Aug 15, 2023 | Feb 14, 2024 | Feb 14, 2024 | 5.2.10 | EOL | |
| 5.1 | Feb 16, 2023 | Aug 14, 2023 | Aug 14, 2023 | 5.1.11 | EOL | |
| 5.0 | Aug 18, 2022 | Feb 14, 2023 | Feb 14, 2023 | 5.0.10 | EOL |
CVEs affecting Contao 5.x (0)
Contao 5.x will reach end of life — migrate to Contao 6.x
Contao 6.x is the next major release. Plan your upgrade before Contao 5.x stops receiving security patches.
Frequently asked questions
Is Contao 5 end of life?
Partially. Some Contao 5.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Contao 5?
No CVEs are currently tracked for Contao 5.x in our database. This may mean no vulnerabilities have been recorded yet, or the data is still syncing.
What is the latest Contao 5 version?
The latest Contao 5.x patch release is 5.7.13, released on August 31, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Contao 5 to Contao 6?
To migrate from Contao 5 to Contao 6: (1) review the official Contao 6 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Contao 5 in production?
Contao 5 is still supported and safe for production use until February 14, 2030. Ensure you are running the latest patch version (5.7.13) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
