216.73.216.6

CVE-2025-65961

· Published 25/11/2025 19:15 · Modified 03/12/2025 18:20

Labels: CVE-2025-65961 2025-11-25CVE-2025-65961CWE-79CWE-87[email protected]

Essential information

Published
25/11/2025 19:15
Modified
03/12/2025 18:20
Author
Creator
CVSS
3.3 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves not using the affected templates or patch them manually.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
contao / contao cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
contao / contao cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
contao / contao cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*

References