Improper Neutralization of Alternate XSS Syntax in Contao - CVE-2025-65961

 

Improper Neutralization of Alternate XSS Syntax in Contao - CVE-2025-65961

Published: May 5, 2026


Vulnerability identifier: #VU130150
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-65961
CWE-ID: CWE-87
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute script code in the browser in the front end and back end.

The vulnerability exists due to improper neutralization of alternate xss syntax in templates when rendering template output. A remote privileged user can inject code into the template output to execute script code in the browser in the front end and back end.


Affected software

Contao

How to mitigate CVE-2025-65961

Install security update from vendor's website.

Contao - addressed in versions 4.13.57, 5.3.42, 5.6.5

External References

Related Security Bulletins