Cross-Site Scripting Vulnerability in Contao Open Source CMS
CVE-2026-107845
9.3CRITICAL
What is CVE-2026-107845?
An issue exists in Contao CMS versions 4.0.0 through 5.3.50 and 5.7.12, allowing unauthenticated users to inject malicious scripts via comment metadata. The vulnerability arises when the comments module improperly encodes email or website data, potentially leading to execution of attacker-controlled scripts in the backend when a user accesses the comments section. This exposure is particularly concerning as unpublished comments are still visible to moderators, allowing malicious content to propagate within the session context of legitimate backend users. The vulnerability has been addressed in subsequent versions 5.3.50 and 5.7.12.
Affected Version(s)
contao >= 4.0.0, < 5.3.50 < 4.0.0, 5.3.50
contao >= 5.4.0-RC1, < 5.7.12 < 5.4.0-RC1, 5.7.12
