We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
It is possible to inject code into the template output that will be executed in the browser in the front end and back end.
Update to Contao 4.13.57, 5.3.42 or 5.6.5
Do not use the affected templates or patch them manually.
https://contao.org/en/security-advisories/cross-site-scripting-in-templates
Impact
It is possible to inject code into the template output that will be executed in the browser in the front end and back end.
Patches
Update to Contao 4.13.57, 5.3.42 or 5.6.5
Workarounds
Do not use the affected templates or patch them manually.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-templates