by Leo Feyer

Cross-site scripting in the frontend search results

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

A backend user can inject a script into the frontend search results that is executed in the victim's browser.

Affected versions

Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

Workaround

Disable the frontend search.

More information

https://github.com/contao/contao/security/advisories/GHSA-h57j-5f5m-789v