{"id":"CVE-2020-25768","details":"Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.","aliases":["GHSA-f7wm-x4gw-6m23"],"modified":"2026-08-07T15:12:10.509906Z","published":"2020-10-07T21:15:14.963Z","references":[{"type":"ADVISORY","url":"https://community.contao.org/en/forumdisplay.php?4-Announcements"},{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/insert-tag-injection-in-forms.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/contao/contao","events":[{"introduced":"84b2fe637d5ead531f117f26b48d1b9de8df4074"},{"fixed":"5552147901fac8affad51662a1bf75a730368eb1"},{"introduced":"23899ad910aa057494cce4517015aa31faa37f11"},{"fixed":"59dd103ad9c1e054fd19737306ab94bcdc87d03f"},{"introduced":"5a25b1d689ffde95a00427bdfde03695a2c645c3"},{"fixed":"ef6296b34581de1c617369b1f61ad3f6a70a4b5c"}],"database_specific":{"cpe":"cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0"},{"fixed":"4.4.52"},{"introduced":"4.9.0"},{"fixed":"4.9.6"},{"introduced":"4.10.0"},{"fixed":"4.10.1"}],"source":"CPE_RANGE"}}],"versions":["4.10.0","4.9.5","4.9.4","4.9.3","4.9.2","4.9.1","4.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25768.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}