Vigilance.fr - Contao: Cross Site Scripting via SVG Uploads, analyzed on 18/03/2025
An attacker can trigger a Cross Site Scripting of Contao, via SVG Uploads, in order to run JavaScript code in the context of the web site. - Security Vulnerability

An attacker can trigger a Cross Site Scripting of Contao, via SVG Uploads, in order to run JavaScript code in the context of the web site.