Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-107845: Contao comments module can run attacker script
CVE-2026-107845 · published today
Summary
The Contao content system (versions 4.0.0 through 5.3.49 and 5.7.11) lets anyone post a comment that includes malicious code. When an administrator views the Comments section, that code can run in their browser, potentially giving the attacker access to the admin's session. Update Contao to the latest release or apply the provided patch to stop this behavior.
What to do
- Update contao comments-bundle to version 5.3.50.
- Update contao comments-bundle to version 5.7.12.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | contao | contao | >= 4.0.0, < 5.3.50 |
| composer | contao | comments-bundle |
>= 4.0.0, < 5.3.50 >= 5.4.0-RC1, < 5.7.12 Fix: upgrade to 5.3.50
|
Original advisory text
Contao: Cross-site scripting in the comments bundle
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
References
- https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a Patch
- https://github.com/contao/contao/releases/tag/5.3.50 URL
- https://github.com/contao/contao/releases/tag/5.7.12 URL
- https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r Vendor Advisory
- https://github.com/advisories/GHSA-628f-v4f6-p37r
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-1078... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-107845 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
CWE-116Improper Encoding or Escaping of Output
Timeline
Published9 Oct 2026
Updated10 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-107845 · NVD
CVE-2026-107845 · MITRE
GHSA-628f-v4f6-p37r · GHSA
CVE-2026-107845 · OSV
Track software like this
Free during beta