CVE-2026-107845Critical· 9.3▾ MidnightContao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comm…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
contao/comments-bundle >= 4.0.0, < 5.3.50contao/comments-bundle >= 5.4.0-RC1, < 5.7.12Patched in:
contao/comments-bundle 5.3.50contao/comments-bundle 5.7.12Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107844Medium· 5.3Contao is an Open Source CMS
CVE-2026-107843Medium· 5.3Contao is an Open Source CMS
CVE-2026-107842Medium· 5.3Contao is an Open Source CMS
CVE-2026-107851Medium· 4.3Contao: Improper access control in the table access voter
CVE-2026-107850Medium· 4.3Contao: Improper access control in the preview links module
CVE-2026-107848Low· 3.5Contao: Cross-site request forgery in custom backend actions