CRITICAL
9.3 CVE-2026-107845 Published 9 Oct 2026
Contao CMS Stored XSS Vulnerability in Comment Moderation
Worried this affects your website?
Contao, an open source CMS, has a stored XSS vulnerability in its comment moderation feature.
From version 4.0.0 through 5.3.50 and 5.7.12:
- An unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php.
- When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session.
- Unpublished comments remain visible to moderators, so moderation does not prevent exposure.
This issue is fixed in versions 5.3.50 and 5.7.12.
Reference: CVE-2026-107845 on NVD
← Back to Security News