High severity7.2NVD Advisory· Published May 6, 2022· Updated Jun 17, 2026
CVE-2022-24899
CVE-2022-24899
Description
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
contao/core-bundlePackagist | >= 4.13.0, < 4.13.3 | 4.13.3 |
contao/contaoPackagist | >= 4.13.0, < 4.13.3 | 4.13.3 |
Affected products
4- ghsa-coords2 versions
>= 4.13.0, < 4.13.3+ 1 more
- (no CPE)range: >= 4.13.0, < 4.13.3
- (no CPE)range: >= 4.13.0, < 4.13.3
Patches
Vulnerability mechanics
References
7- github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cnvdPatchThird Party AdvisoryWEB
- contao.org/en/security-advisories/cross-site-scripting-via-canonical-url.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-m8x6-6r63-qvj2ghsaADVISORY
- github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-24899ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2022-24899.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2022-24899.yamlghsaWEB
News mentions
0No linked articles in our index yet.