Disclosure summary
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.
Source-reported weakness categories
CWE-204, CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-mfxh-vp55-7gc6
Open original source · Updated Oct 09, 2026
Contao: The registration module re-sends activation mails
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | contao/core-bundle | >= 4.1.0, < 5.3.50 | 5.3.50 |
| composer | contao/core-bundle | >= 5.4.0-RC1, < 5.7.12 | 5.7.12 |
NIST National Vulnerability Database · NVD-CVE-2026-107843
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-09T16:17:10-04:00
MODIFIED 2026-10-09T16:17:10-04:00
INGESTED 2026-10-10T20:55:12-04:00