CVE-2026-107843
Contao: The registration module re-sends activation mails on any unauthenticated POST, with no throttle and no captcha check
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.
| CWE | CWE-204 CWE-770 |
| Vendor | contao |
| Product | contao |
| Published | Oct 9, 2026 |
Get instant alerts for contao contao
Be the first to know when new medium vulnerabilities affecting contao contao are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N