{"api_version":"1","generated_at":"2026-10-09T21:32:40+00:00","cve":"CVE-2026-107845","urls":{"html":"https://cve.report/CVE-2026-107845","api":"https://cve.report/api/cve/CVE-2026-107845.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107845","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107845"},"summary":{"title":"Contao: Cross-site scripting in the comments bundle","description":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-09 20:17:10","updated_at":"2026-10-09 20:17:10"},"problem_types":["CWE-79","CWE-116","CWE-79 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","CWE-116 CWE-116: Improper Encoding or Escaping of Output"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.3,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r","name":"https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","name":"https://github.com/contao/contao/releases/tag/5.7.12","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a","name":"https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/contao/contao/releases/tag/5.3.50","name":"https://github.com/contao/contao/releases/tag/5.3.50","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107845","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107845","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"contao","product":"contao","version":"affected >= 4.0.0, < 5.3.50","platforms":[]},{"source":"CNA","vendor":"contao","product":"contao","version":"affected >= 5.4.0-RC1, < 5.7.12","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-107845","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-10-09T19:51:37.559746Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-09T19:51:45.890Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"contao","vendor":"contao","versions":[{"status":"affected","version":">= 4.0.0, < 5.3.50"},{"status":"affected","version":">= 5.4.0-RC1, < 5.7.12"}]}],"descriptions":[{"lang":"en","value":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.3,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-116","description":"CWE-116: Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-09T19:29:55.396Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r"},{"name":"https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a","tags":["x_refsource_MISC"],"url":"https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a"},{"name":"https://github.com/contao/contao/releases/tag/5.3.50","tags":["x_refsource_MISC"],"url":"https://github.com/contao/contao/releases/tag/5.3.50"},{"name":"https://github.com/contao/contao/releases/tag/5.7.12","tags":["x_refsource_MISC"],"url":"https://github.com/contao/contao/releases/tag/5.7.12"}],"source":{"advisory":"GHSA-628f-v4f6-p37r","discovery":"UNKNOWN"},"title":"Contao: Cross-site scripting in the comments bundle"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-107845","datePublished":"2026-10-09T19:29:55.396Z","dateReserved":"2026-10-08T22:34:49.291Z","dateUpdated":"2026-10-09T19:51:45.890Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-09 20:17:10","lastModifiedDate":"2026-10-09 20:17:10","problem_types":["CWE-79","CWE-116","CWE-79 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","CWE-116 CWE-116: Improper Encoding or Escaping of Output"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-09T19:51:37.559746Z","id":"CVE-2026-107845","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107845","Ordinal":"1","Title":"Contao: Cross-site scripting in the comments bundle","CVE":"CVE-2026-107845","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107845","Ordinal":"1","NoteData":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.","Type":"Description","Title":"Contao: Cross-site scripting in the comments bundle"}]}}}