CVE-2025-65960: Contao is vulnerable to remote code execution in template closures
Impact
Backend users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters.
Patches
Update to Contao 4.13.57, 5.3.42 or 5.6.5
Workarounds
Manually patch the Contao\Template::once() method.
Resources
https://contao.org/en/security-advisories/remote-code-execution-in-template-closures
Other sources
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65960?
CVE-2025-65960 is categorized as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-65960?
To remediate CVE-2025-65960, you should upgrade Contao to version 4.13.57 or later, 5.3.42 or later, or 5.6.5 or later.
What are the potential impacts of CVE-2025-65960?
The exploitation of CVE-2025-65960 allows authenticated back end users to execute arbitrary PHP functions, which could compromise the entire system.
Who is affected by CVE-2025-65960?
All users running Contao versions from 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5 are vulnerable to CVE-2025-65960.
Is CVE-2025-65960 patched?
Yes, CVE-2025-65960 has been patched in the latest versions of Contao.