AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107845.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.3CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSReceivedModified Oct 09, 2026

Disclosure summary

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.

Source-reported weakness categories

CWE-79, CWE-116

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-628f-v4f6-p37r

Open original source · Updated Oct 09, 2026

Contao: Cross-site scripting in the comments bundle

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
composercontao/comments-bundle>= 4.0.0, < 5.3.505.3.50
composercontao/comments-bundle>= 5.4.0-RC1, < 5.7.125.7.12
NIST National Vulnerability Database · NVD-CVE-2026-107845

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-09T16:17:10-04:00
MODIFIED 2026-10-09T16:17:10-04:00
INGESTED 2026-10-10T20:55:12-04:00