Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.
References
| Link | Resource |
|---|---|
| https://contao.org/en/security-advisories/remote-code-execution-in-template-closures | Vendor Advisory |
| https://github.com/contao/contao/security/advisories/GHSA-98vj-mm79-v77r | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Dec 2025, 17:55
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Contao
Contao contao |
|
| CPE | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
| References | () https://contao.org/en/security-advisories/remote-code-execution-in-template-closures - Vendor Advisory | |
| References | () https://github.com/contao/contao/security/advisories/GHSA-98vj-mm79-v77r - Vendor Advisory |
25 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-25 19:15
Updated : 2025-12-03 17:55
NVD link : CVE-2025-65960
Mitre link : CVE-2025-65960
CVE.ORG link : CVE-2025-65960
JSON object : View
Products Affected
contao
- contao
CWE
CWE-351
Insufficient Type Distinction
