Insufficient Type Distinction Affecting contao/core-bundle package, versions <4.13.57>=5.0.0-RC1, <5.3.42>=5.4.0-RC1, <5.6.5


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-CONTAOCOREBUNDLE-14121795
  • published27 Nov 2025
  • disclosed25 Nov 2025
  • creditMartin Auswöger, M. Vondano

Introduced: 25 Nov 2025

NewCVE-2025-65960  (opens in a new tab)
CWE-351  (opens in a new tab)

How to fix?

Upgrade contao/core-bundle to version 4.13.57, 5.3.42, 5.6.5 or higher.

Overview

contao/core-bundle is an Open Source PHP Content Management System for people who want a professional website that is easy to maintain.

Affected versions of this package are vulnerable to Insufficient Type Distinction in the Template::once() method. Backend users with sufficient privileges can execute arbitrary PHP functions without required parameters by manipulating the contents of template closures.

CVSS Base Scores

version 4.0
version 3.1