PT-2026-109305 · Contao · Contao
CVE-2026-107845
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Contao versions 4.0.0 through 5.3.49
Contao versions 5.7.0 through 5.7.11
Description
An unauthenticated visitor can submit a comment containing a Cross-Site Scripting (XSS) injection. The issue occurs because the
listComments() function in comments-bundle/contao/dca/tl comments.php renders email or website metadata without sufficient attribute and URL encoding. When a backend user opens the Comments module, an attacker-controlled script executes within the backend origin under that user's session. Because unpublished comments remain visible to moderators, the moderation process does not prevent exposure and instead ensures the moderator encounters the payload. The absence of a Content-Security-Policy header in the backend further allows the execution of inline handlers. This can lead to unauthorized actions such as reading modules, creating new administrators, or editing templates to achieve code execution.Recommendations
Update to version 5.3.50 or 5.7.12.
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contao