Vulnerability GHSA-68q5-78xp-cwwc
Low Risk
LOW RISK
CVSS Score: 3.3
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
10 months ago
November 25, 2025 at 08:48 PM UTC
Contao is vulnerable to cross-site scripting in templates
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4
Summary
Contao is vulnerable to cross-site scripting in templates
Details
Impact
It is possible to inject code into the template output that will be executed in the browser in the front end and back end.
Patches
Update to Contao 4.13.57, 5.3.42 or 5.6.5.
Workarounds
Do not use the affected templates or patch them manually.
Refsources
https://contao.org/en/security-advisories/cross-site-scripting-in-templates
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
3 days ago
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao crawler leaks auth credentials to external hosts
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
Medium Risk
10 months ago
Contao is vulnerable to remote code execution in template closures
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-98vj-mm79-v77r
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-98vj-mm79-v77r
Medium Risk
1 year ago
Contao does not properly manage privileges for page and article fields
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 GHSA-qqfq-7cpp-hcqj
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 GHSA-qqfq-7cpp-hcqj
Impacted packages
Timeline
Published
10 months ago
November 25, 2025 at 08:48 PM UTC
Fixed (5.3.42)
10 months ago
November 25, 2025 at 03:32 PM UTC
Fixed (4.13.57)
10 months ago
November 25, 2025 at 03:43 PM UTC
Fixed (5.6.5)
10 months ago
November 25, 2025 at 04:01 PM UTC
Last Modified
9 months ago
December 03, 2025 at 07:31 PM UTC