PatchSiren cyber security CVE debrief
CVE-2026-107845 contao CVE debrief
A Cross-site scripting vulnerability exists in Contao's comments bundle from version 4.0.0 until 5.3.50 and 5.7.12. An unauthenticated visitor can submit a comment with malicious email or website metadata that can execute script in the Contao backend origin under a backend user's session when they open the Comments module. The vulnerability allows attackers to inject malicious scripts, potentially leading to unauthorized actions within the backend. This issue is particularly concerning as it can be exploited without authentication, making it a critical concern for Contao administrators.
- Vendor
- contao
- Product
- Unknown
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Contao administrators, backend users, and security teams should assess exposure and apply patches to prevent exploitation. Additionally, they should review and update backend user sessions and access controls, monitor for suspicious activity in the Comments module, and conduct a thorough review of existing comments for potential malicious content.
Why it matters
Defenders should prioritize verifying exposure in Contao installations and applying patches to prevent exploitation, as this vulnerability allows script execution in the backend origin under a backend user's session.
- Potential script execution in the Contao backend origin under a backend user's session
- Exposure of backend user sessions and access controls
- Possible exploitation through malicious comment metadata
Technical summary
The vulnerability exists in the comments bundle of Contao, allowing an unauthenticated visitor to submit a comment with malicious email or website metadata. When a backend user opens the Comments module, the attacker-controlled script can execute in the Contao backend origin under that user's session. This is due to insufficient attribute and URL encoding in the listComments() function within comments-bundle/contao/dca/tl_comments.php. The issue affects Contao versions from 4.0.0 to 5.3.50 and 5.7.12, and it is fixed in versions 5.3.50 and 5.7.12.
Defensive priority
Defenders should prioritize verifying exposure in Contao installations and applying patches to prevent exploitation.
Recommended defensive actions
- Verify Contao version and apply patches to vulnerable installations
- Review and update backend user sessions and access controls
- Monitor for suspicious activity in the Comments module
- Conduct a thorough review of existing comments for potential malicious content
- Implement additional logging and monitoring for backend user activities
- Consider temporarily disabling comment functionality until patches are applied
- Perform a comprehensive security audit of Contao installations
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify Contao installations, review backend user sessions, and monitor for suspicious activity. The lack of detailed information on exploitation or impact necessitates a cautious approach, focusing on patching and enhanced monitoring.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107845 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107845
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107845 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107845
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Contao: Cross-site scripting in the comments bundle
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107845.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/releases/tag/5.3.50
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/contao/contao/releases/tag/5.7.12
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.