Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves not using the affected templates or patch them manually.
References
| Link | Resource |
|---|---|
| https://contao.org/en/security-advisories/cross-site-scripting-in-templates | Vendor Advisory |
| https://github.com/contao/contao/security/advisories/GHSA-68q5-78xp-cwwc | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Dec 2025, 18:20
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CPE | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
| References | () https://contao.org/en/security-advisories/cross-site-scripting-in-templates - Vendor Advisory | |
| References | () https://github.com/contao/contao/security/advisories/GHSA-68q5-78xp-cwwc - Vendor Advisory | |
| First Time |
Contao
Contao contao |
25 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-25 19:15
Updated : 2025-12-03 18:20
NVD link : CVE-2025-65961
Mitre link : CVE-2025-65961
CVE.ORG link : CVE-2025-65961
JSON object : View
Products Affected
contao
- contao
