by Leo Feyer
Cross-site scripting in the frontend search results
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
A backend user can inject a script into the frontend search results that is executed in the victim's browser.
Affected versions
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
Workaround
Disable the frontend search.
More information
https://github.com/contao/contao/security/advisories/GHSA-h57j-5f5m-789v