๐Ÿ” CVE Alert

CVE-2026-107845

CRITICAL 9.3

Contao: Cross-site scripting in the comments bundle

CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.

CWE CWE-79 CWE-116
Vendor contao
Product contao
Published Oct 9, 2026
Last Updated Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for contao contao

Be the first to know when new critical vulnerabilities affecting contao contao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

contao / contao
>= 4.0.0, < 5.3.50 >= 5.4.0-RC1, < 5.7.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r github.com: https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a github.com: https://github.com/contao/contao/releases/tag/5.3.50 github.com: https://github.com/contao/contao/releases/tag/5.7.12