CVE-2026-107845
Received Received - Intake

Stored Cross-Site Scripting in Contao CMS

Vulnerability report for CVE-2026-107845, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
contao contao >= 4.0.0, < 5.3.50
contao contao >= 5.4.0-RC1, < 5.7.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a cross-site scripting (XSS) vulnerability in Contao CMS versions 4.0.0 to 5.3.50 and 5.7.12. An unauthenticated attacker can submit a comment with malicious script in the email or website field. When a backend user views the Comments module, the script executes in the Contao backend under that user's session due to insufficient encoding of user input.

Detection Guidance

Check Contao versions with: grep -r "version" vendor/contao/contao/composer.json. Inspect comments in the backend for unusual scripts or payloads in email/website fields. Review server logs for repeated comment submissions from the same IP.

Impact Analysis

An attacker could steal session cookies, perform actions as the victim user like creating administrators or editing templates, read sensitive modules, or execute arbitrary code. The attack requires user interaction (opening the Comments module) but no authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. The potential for data theft or modification may result in compliance breaches.

Mitigation Strategies

Upgrade Contao to versions 5.3.50 or 5.7.12 immediately. Apply the patch from commit 22505d5 if manual update is not possible. Monitor backend sessions for suspicious activity and restrict comment moderation access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107845. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart