CRITICAL 9.3 CVE-2026-107845 Published 9 Oct 2026

Contao CMS Stored XSS Vulnerability in Comment Moderation

Worried this affects your website?

Contao, an open source CMS, has a stored XSS vulnerability in its comment moderation feature.

From version 4.0.0 through ‍5.3.50 and ‍5.7.12:

  • An unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php.
  • When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session.
  • Unpublished comments remain visible to moderators, so moderation does not prevent exposure.

This issue is fixed in versions 5.3.50 and ‍5.7.12.

Reference: CVE-2026-107845 on NVD

← Back to Security News