Users can upload SVG files with malicious code, which is then executed in the back end and/or front end.
Update to Contao 4.13.54, 5.3.30 or 5.5.6.
Remove svg,svgz from the allowed upload file types in the system settings and from contao.editable_files in the config.yaml.
https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads
If you have any questions or comments about this advisory, open an issue in contao/contao.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2025-03-18T21:07:17Z",
"nvd_published_at": "2025-03-18T19:15:50Z",
"severity": "MODERATE"
}