Vulnerability GHSA-68q5-78xp-cwwc

Low Risk
LOW RISK
CVSS Score: 3.3
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
10 months ago
November 25, 2025 at 08:48 PM UTC
Contao is vulnerable to cross-site scripting in templates
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4

Summary

Contao is vulnerable to cross-site scripting in templates

Details

Impact

It is possible to inject code into the template output that will be executed in the browser in the front end and back end.

Patches

Update to Contao 4.13.57, 5.3.42 or 5.6.5.

Workarounds

Do not use the affected templates or patch them manually.

Refsources

https://contao.org/en/security-advisories/cross-site-scripting-in-templates

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Low Risk
3 days ago
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao crawler leaks auth credentials to external hosts
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
Medium Risk
10 months ago
Contao is vulnerable to remote code execution in template closures
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-98vj-mm79-v77r
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-98vj-mm79-v77r
Medium Risk
1 year ago
Contao does not properly manage privileges for page and article fields
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 GHSA-qqfq-7cpp-hcqj
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 GHSA-qqfq-7cpp-hcqj
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
10 months ago
November 25, 2025 at 08:48 PM UTC
Fixed (5.3.42)
10 months ago
November 25, 2025 at 03:32 PM UTC
Fixed (4.13.57)
10 months ago
November 25, 2025 at 03:43 PM UTC
Fixed (5.6.5)
10 months ago
November 25, 2025 at 04:01 PM UTC
Last Modified
9 months ago
December 03, 2025 at 07:31 PM UTC