{"id":"CVE-2021-35955","details":"Contao \u003e=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.","aliases":["GHSA-hr3h-x6gq-rqcp"],"modified":"2026-08-07T16:57:27.203127Z","published":"2021-08-12T15:15:07.960Z","references":[{"type":"ADVISORY","url":"https://contao.org/en/news/contao-4-9-16-and-4-11-5-are-available.html"},{"type":"ADVISORY","url":"https://github.com/contao/contao/security/advisories/GHSA-hr3h-x6gq-rqcp"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/contao/contao","events":[{"introduced":"84b2fe637d5ead531f117f26b48d1b9de8df4074"},{"fixed":"d4b1299fa180b522613a78cd9b192c3ccdb28448"},{"introduced":"b09b4d51d13d37b4bfcd2ef4314fc6a20184dc55"},{"fixed":"1a1e7bb2050f08b2814de68efae4f11c3256c853"},{"introduced":"5a25b1d689ffde95a00427bdfde03695a2c645c3"},{"fixed":"7715fdfd3d1dda3ec1e3d9a02a2bd535983ac7fc"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.4.56"},{"introduced":"4.5.0"},{"fixed":"4.9.18"},{"introduced":"4.10.0"},{"fixed":"4.11.7"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-35955.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}