MEDIUM🇵🇱 Wersja polska

CVE-2025-65960

CVSS 6.6v3.1pub. 2025-11-25upd. 2025-12-03

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Contao

    APP
    Contao
    4.0.0 – 4.13.57 (excl.)5.0.0 – 5.3.42 (excl.)5.4.0 – 5.6.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-26265CRITICAL9.8PL ✓same product

RCE poprzez command injection w parametrze php_cli w Contao Managed Edition

CVE-2019-11512CRITICAL9.8PL ✓same product

SQL Injection w Contao 4.x — krytyczna podatność bazy danych

CVE-2024-45398HIGH8.3same product

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload ...

CVE-2024-28235HIGH8.3same product

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 an...

CVE-2022-24899HIGH7.2same product

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applicat...