CVE-2026-107845
Contao: Cross-site scripting in the comments bundle
CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
| CWE | CWE-79 CWE-116 |
| Vendor | contao |
| Product | contao |
| Published | Oct 9, 2026 |
| Last Updated | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for contao contao
Be the first to know when new critical vulnerabilities affecting contao contao are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
contao / contao
>= 4.0.0, < 5.3.50 >= 5.4.0-RC1, < 5.7.12
References
github.com: https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r github.com: https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a github.com: https://github.com/contao/contao/releases/tag/5.3.50 github.com: https://github.com/contao/contao/releases/tag/5.7.12