Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-107845: Contao comments module can run attacker script

CVE-2026-107845 · published today
Summary

The Contao content system (versions 4.0.0 through 5.3.49 and 5.7.11) lets anyone post a comment that includes malicious code. When an administrator views the Comments section, that code can run in their browser, potentially giving the attacker access to the admin's session. Update Contao to the latest release or apply the provided patch to stop this behavior.

What to do
  • Update contao comments-bundle to version 5.3.50.
  • Update contao comments-bundle to version 5.7.12.
Affected software
Ecosystem VendorProductAffected versions
– contao contao >= 4.0.0, < 5.3.50
composer contao comments-bundle >= 4.0.0, < 5.3.50
>= 5.4.0-RC1, < 5.7.12
Fix: upgrade to 5.3.50
Original advisory text
Contao: Cross-site scripting in the comments bundle
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Type
CWE-79Cross-site Scripting (XSS)
CWE-116Improper Encoding or Escaping of Output
Timeline
Published9 Oct 2026
Updated10 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-107845 · MITRE
Track software like this
Free during beta