Medium severity4.3NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2024-28234
CVE-2024-28234
Description
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable BBCode for comments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
contao/comments-bundlePackagist | >= 2.0.0, < 4.13.40 | 4.13.40 |
contao/comments-bundlePackagist | >= 5.0.0-RC1, < 5.3.4 | 5.3.4 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/contao/contao/commit/55b995d8d35da0d36bc6a22c53fe6423ab0c4ae2nvdPatchWEB
- github.com/contao/contao/commit/6d42e667177c972ae7c219645593c262d7764ce2nvdPatchWEB
- contao.org/en/security-advisories/insufficient-bbcode-sanitizationnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-j55w-hjpj-825gghsaADVISORY
- github.com/contao/contao/security/advisories/GHSA-j55w-hjpj-825gnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-28234ghsaADVISORY
News mentions
0No linked articles in our index yet.