Cross-Site Scripting Vulnerability in Contao Open Source CMS
CVE-2026-107845

9.3CRITICAL

Key Information:

Vendor

Contao

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107845?

An issue exists in Contao CMS versions 4.0.0 through 5.3.50 and 5.7.12, allowing unauthenticated users to inject malicious scripts via comment metadata. The vulnerability arises when the comments module improperly encodes email or website data, potentially leading to execution of attacker-controlled scripts in the backend when a user accesses the comments section. This exposure is particularly concerning as unpublished comments are still visible to moderators, allowing malicious content to propagate within the session context of legitimate backend users. The vulnerability has been addressed in subsequent versions 5.3.50 and 5.7.12.

Affected Version(s)

contao >= 4.0.0, < 5.3.50 < 4.0.0, 5.3.50

contao >= 5.4.0-RC1, < 5.7.12 < 5.4.0-RC1, 5.7.12

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.