Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 52.4%