Looking for the vulnerability index of Invicti's legacy products?
Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-29790 - Vulnerability Database

Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-29790

Medium
Reference: CVE-2025-29790
Title: Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Contao is an Open Source CMS. Users can upload SVG files with malicious code which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54 5.3.30 or 5.5.6.