CVE-2025-29790
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
MEDIUM · CVSS 5.4
EPSS 0.00533
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0