CVE-2025-65961
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves not using the affected templates or patch them manually.
Scoring
- Severity
- LOW
- CVSS base score
- 3.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-87
- Published
- 2025-11-25
- Last modified
- 2026-03-12
Affected products
- contao contao
- contao contao
- contao contao
Weakness type
Related vulnerabilities
- CVE-2026-79946 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-54002 — Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
- CVE-2026-55661 — TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
- CVE-2026-55237 — AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
- CVE-2026-46492 — md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
- CVE-2026-25688 — Apache Answer: XSS in AI Answer Rendering
- CVE-2026-45314 — Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
- CVE-2026-42458 — Magento LTS: Reflected XSS - Import -> Data Flow (profiles)