---
id: CVE-2026-107845
title: Contao is an Open Source CMS
summary: >-
  Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an
  unauthenticated visitor can submit a comment whose email or website metadata
  is rendered without sufficient attribute and URL encoding by listComments() in
  comm…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
  - CWE-116
vendor: contao
product: contao/comments-bundle
affected:
  - 'contao/comments-bundle >= 4.0.0, < 5.3.50'
  - 'contao/comments-bundle >= 5.4.0-RC1, < 5.7.12'
patched:
  - contao/comments-bundle 5.3.50
  - contao/comments-bundle 5.7.12
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:17:10.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107845'
references:
  - url: >-
      https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/releases/tag/5.3.50'
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/releases/tag/5.7.12'
    label: security-advisories@github.com
  - url: 'https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-628f-v4f6-p37r'
tags:
  - nvd
  - ghsa
  - composer
aliases:
  - GHSA-628f-v4f6-p37r
ecosystem: composer
ingestedAt: '2026-10-09T21:12:42.318Z'
---

## Overview

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107845)

Affected packages:

- `contao/comments-bundle >= 4.0.0, < 5.3.50`
- `contao/comments-bundle >= 5.4.0-RC1, < 5.7.12`

Patched in:

- `contao/comments-bundle 5.3.50`
- `contao/comments-bundle 5.7.12`

Source: https://github.com/advisories/GHSA-628f-v4f6-p37r
