Users can upload SVG files with malicious code, which is then executed in the back end and/or front end.
Update to Contao 4.13.54, 5.3.30 or 5.5.6.
Remove svg,svgz
from the allowed upload file types in the system settings and from contao.editable_files
in the config.yaml
.
https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads
If you have any questions or comments about this advisory, open an issue in contao/contao.
{ "nvd_published_at": "2025-03-18T19:15:50Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-03-18T21:07:17Z" }