Disclosure summary
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
Source-reported weakness categories
CWE-79, CWE-116
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-628f-v4f6-p37r
Open original source · Updated Oct 09, 2026
Contao: Cross-site scripting in the comments bundle
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | contao/comments-bundle | >= 4.0.0, < 5.3.50 | 5.3.50 |
| composer | contao/comments-bundle | >= 5.4.0-RC1, < 5.7.12 | 5.7.12 |
NIST National Vulnerability Database · NVD-CVE-2026-107845
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-09T16:17:10-04:00
MODIFIED 2026-10-09T16:17:10-04:00
INGESTED 2026-10-10T20:55:12-04:00