Cross-Site Scripting Vulnerability in Contao CMS
CVE-2025-29790
4.8MEDIUM
What is CVE-2025-29790?
Contao, an Open Source Content Management System, has a security flaw that permits users to upload SVG files embedded with malicious code. This malicious code could execute in both the backend and frontend environments, potentially compromising the integrity and security of the website. The issue has been addressed in the latest updates, specifically in versions 4.13.54, 5.3.30, and 5.5.6.
Affected Version(s)
contao >= 4.0.0, < 4.13.54 < 4.0.0, 4.13.54
contao >= 5.0.0, < 5.3.30 < 5.0.0, 5.3.30
contao >= 5.4.0, < 5.5.6 < 5.4.0, 5.5.6
