CVE-2025-65961

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves not using the affected templates or patch them manually.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*

History

03 Dec 2025, 18:20

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
References () https://contao.org/en/security-advisories/cross-site-scripting-in-templates - () https://contao.org/en/security-advisories/cross-site-scripting-in-templates - Vendor Advisory
References () https://github.com/contao/contao/security/advisories/GHSA-68q5-78xp-cwwc - () https://github.com/contao/contao/security/advisories/GHSA-68q5-78xp-cwwc - Vendor Advisory
First Time Contao
Contao contao

25 Nov 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 19:15

Updated : 2025-12-03 18:20


NVD link : CVE-2025-65961

Mitre link : CVE-2025-65961

CVE.ORG link : CVE-2025-65961


JSON object : View

Products Affected

contao

  • contao
CWE
CWE-87

Improper Neutralization of Alternate XSS Syntax

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')