VulnerabilityAnalyzed
CVE-2025-29790
Users can upload SVG files with malicious code, which is then executed in the back end and/or front end.
MEDIUM 4.8EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.22% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- contao/contao
- Source
- security-advisories@github.com
References
- https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploadsVendor Advisory
- https://github.com/contao/contao/security/advisories/GHSA-vqqr-fgmh-f626Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.