Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-29790
Contao is an Open Source CMS. Users can upload SVG files with malicious code which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54 5.3.30 or 5.5.6.