CVE-2025-65960
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.18%
- CWE
- CWE-351
- Published
- 2025-11-25
- Last modified
- 2026-03-12
Affected products
- contao contao
- contao contao
- contao contao
Weakness type
Related vulnerabilities
- CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2026-41341 — OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
- CVE-2025-54413 — skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-54412 — skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
- CVE-2025-47939 — TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
- CVE-2025-30510 — Growatt Cloud portal Insufficient Type Distinction
- CVE-2025-32035 — DNN does not check the contents of a file when uploading files