6.6

CVE-2025-65960

Contao is vulnerable to remote code execution in template closures

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ContaoContao Version >= 4.0.0 < 4.13.57
ContaoContao Version >= 5.0.0 < 5.3.42
ContaoContao Version >= 5.4.0 < 5.6.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.05
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-351 Insufficient Type Distinction

The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.

https://github.com/contao/contao/security/advisories/GHSA-98vj-mm79-v77r
Vendor Advisory
https://contao.org/en/security-advisories/remote-code-execution-in-template-closures
Vendor Advisory