Cross-site scripting in Contao - CVE-2025-29790
Published: March 18, 2025 / Updated: May 5, 2026
Contao
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script code in the back end and/or front end.
The vulnerability exists due to cross-site scripting in SVG file upload handling when processing uploaded SVG files. A remote user can upload a malicious SVG file to execute arbitrary script code in the back end and/or front end.
User interaction is required for the malicious SVG content to be executed.