← Vulnerability feed

Vulnerability record · CVE-2025-65960 · published 25 November 2025

CVE-2025-65960: Contao vulnerability

Contao · Contao

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.

6.6 CVSS 3.1 Medium EPSS 0.18% · top 93.5% CWE-351 · CWE-351
6.6CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-65960 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26265Contao os command injection vulnerabilityContao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.EPSS 30%9.8CVE-2019-11512Contao sql injection vulnerabilityContao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.EPSS 1.5%8.8CVE-2024-45398Contao unrestricted file upload vulnerabilityContao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the…EPSS 0.53%8.8CVE-2012-4383Contao sql injection vulnerabilitycontao prior to 2.11.4 has a sql injection vulnerabilityEPSS 0.92%8.8CVE-2019-19745Contao unrestricted file upload vulnerabilityContao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th…EPSS 1.1%7.2CVE-2021-37626Contao code injection vulnerabilityContao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …EPSS 1.3%7.2CVE-2021-37627Contao improper privilege management vulnerabilityContao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r…EPSS 1.0%7.1CVE-2024-30262Contao insufficient session expiration vulnerabilityContao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or t…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2025-65960), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.