PT-2026-109305 · Contao · Contao

CVE-2026-107845

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Contao versions 4.0.0 through 5.3.49 Contao versions 5.7.0 through 5.7.11
Description An unauthenticated visitor can submit a comment containing a Cross-Site Scripting (XSS) injection. The issue occurs because the listComments() function in comments-bundle/contao/dca/tl comments.php renders email or website metadata without sufficient attribute and URL encoding. When a backend user opens the Comments module, an attacker-controlled script executes within the backend origin under that user's session. Because unpublished comments remain visible to moderators, the moderation process does not prevent exposure and instead ensures the moderator encounters the payload. The absence of a Content-Security-Policy header in the backend further allows the execution of inline handlers. This can lead to unauthorized actions such as reading modules, creating new administrators, or editing templates to achieve code execution.
Recommendations Update to version 5.3.50 or 5.7.12.

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107845
GHSA-628F-V4F6-P37R

Affected Products

Contao