CVE-2025-29790Cross-site Scripting in Contao

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 66.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18

Description

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Packages3 packages

NVDcontao/contao4.0.04.13.53+2
Packagistcontao/core-bundle4.0.04.13.54+2
CVEListV5contao/contao>= 4.0.0, < 4.13.54, >= 5.0.0, < 5.3.30, >= 5.4.0, < 5.5.6+2

Patches

🔴Vulnerability Details

3
GHSA
Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads2025-03-18
CVEList
Contao allows cross-site scripting through SVG uploads2025-03-18
OSV
Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads2025-03-18
CVE-2025-29790 — Cross-site Scripting in Contao | cvebase