Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-68q5-78xp-cwwc | Contao is vulnerable to cross-site scripting in templates |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 03 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* |
Thu, 27 Nov 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Vendors & Products |
Contao
Contao contao |
Tue, 25 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves not using the affected templates or patch them manually. | |
| Title | Contao is vulnerable to cross-site scripting in templates | |
| Weaknesses | CWE-87 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-25T19:29:04.630Z
Reserved: 2025-11-18T16:14:56.694Z
Link: CVE-2025-65961
Updated: 2025-11-25T19:28:57.580Z
Status : Analyzed
Published: 2025-11-25T19:15:51.387
Modified: 2025-12-03T18:20:37.613
Link: CVE-2025-65961
No data.
OpenCVE Enrichment
Updated: 2025-11-27T09:45:27Z
Github GHSA