Description
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting that can be executed in the Contao backend under an authenticated moderator’s session
Action: Apply patch
AI Analysis

Impact

The vulnerability is a classic unsanitized output issue that allows any unauthenticated visitor to submit a comment whose email or website fields are rendered directly without proper encoding. When a backend user opens the Comments module, attacker-controlled JavaScript executes in the Contao backend origin with that user’s session privileges. This is a stored XSS that can lead to session hijacking or code execution on the backend, classed under CWE-79 and CWE-116. The impact is malicious script execution in the CMS backend, potentially compromising the accounts of moderator users.

Affected Systems

Affected from Contao CMS version 4.0.0 up to and including the 5.3.49 release and 5.7.11. The fix is delivered in releases 5.3.50 and 5.7.12, so any version newer than 5.3.50 or 5.7.12 is considered safe. The downstream product remains the Contao CMS platform for all affected instances.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is rated critical. The EPSS score is not available, but the lack of a KEV listing does not diminish that the issue is widely usable. An attacker only needs to craft a malicious comment on a publicly exposed comment form; no authentication or privileged access is required. If a moderator or other backend user subsequently opens the Comments module, the stored script runs within that session, giving the attacker the same privileges as the moderator. Because unpublished comments are still visible to moderators, the usual moderation workflow does not mitigate the risk.

Generated by OpenCVE AI on October 9, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Contao 5.3.50 or later (or 5.7.12 if using that series).
  • Disable or restrict public comment submission until the patch is applied, or lock comment visibility so that only moderated comments are visible to backend users.
  • Sanitize or encode the comment’s email and website fields before rendering them, ensuring that any user‑supplied data is output‑escaped in the backend.

Generated by OpenCVE AI on October 9, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
Vendors & Products Contao
Contao contao

Fri, 09 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
Title Contao: Cross-site scripting in the comments bundle
Weaknesses CWE-116
CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T19:51:45.890Z

Reserved: 2026-10-08T22:34:49.291Z

Link: CVE-2026-107845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T20:17:10.457

Modified: 2026-10-09T20:17:10.457

Link: CVE-2026-107845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T20:30:11Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')