Contao prior to 4.13.3 contains a cross-site scripting vulnerability. It is possible to inject arbitrary JavaScript code into the canonical tag.
id: CVE-2022-24899
info:
name: Contao <4.13.3 - Cross-Site Scripting
author: ritikchaddha
sev
...