๐Ÿ” CVE Alert

CVE-2026-107848

LOW 3.5

Contao: Cross-site request forgery in custom backend actions

CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.

CWE CWE-352
Vendor contao
Product contao
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for contao contao

Be the first to know when new low vulnerabilities affecting contao contao are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

contao / contao
>= 4.0.0, < 5.3.50 >= 5.4.0-RC1, < 5.7.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/contao/contao/security/advisories/GHSA-9ff2-p842-45wq github.com: https://github.com/contao/contao/commit/34dd27ee6739f10568d3d95d8784862255c925b4 github.com: https://github.com/contao/contao/releases/tag/5.7.12