Contao: Cross-site scripting in the comments bundle (CVE-2026-107845)
Description
CVE-2026-107845 is a critical cross-site scripting (XSS) vulnerability in the Contao comments bundle that allows unauthenticated front end visitors to inject malicious scripts in comments. These scripts execute in the context of any back end user who opens the Comments module, without requiring any user interaction. The lack of a Content-Security-Policy header on the Contao back end allows inline script execution. This can lead to full back end compromise, including reading modules, creating administrators, or editing templates that enable code execution. Moderation does not prevent exposure and actually guarantees it since unpublished comments are still loaded by moderators. A patch is available for affected versions.
CVSS v3.1
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Contao comments bundle contains a stored cross-site scripting vulnerability (CVE-2026-107845) that permits an unauthenticated visitor to submit a comment with malicious script code. When a back end user opens the Comments module, the injected script executes automatically in their session context due to the absence of Content-Security-Policy headers. This allows the attacker to perform actions with the privileges of the back end user, including reading accessible modules, creating new administrators, or modifying templates that can lead to remote code execution. Moderation does not mitigate the issue because unpublished comments are still rendered, ensuring exposure. The vulnerability affects Contao versions >=4.0.0 <5.3.50 and >=5.4.0-RC1 <5.7.12. A patch is available to remediate this critical security flaw.
Potential Impact
An attacker can inject malicious scripts via comments that execute in the browser of any back end user who views the Comments module, without requiring any interaction. This results in full compromise of the back end user session, allowing the attacker to read data, create new administrators, or modify templates to achieve code execution. The vulnerability effectively allows remote code execution through the back end interface. Moderation does not prevent exploitation and actually ensures exposure of the malicious payload to back end users.
Mitigation Recommendations
A patch is available for this vulnerability and should be applied promptly. Since the vulnerability is in the Contao comments bundle and affects specific versions, upgrading to a fixed version is the recommended remediation. There is no indication that Content-Security-Policy headers are currently implemented, so relying on such mitigations is insufficient. Moderation does not prevent exploitation and should not be relied upon as a mitigation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-628f-v4f6-p37r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-107845"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6ac96e432cdf04f65689a682
Added to database: 10/09/2026, 22:44:19 UTC
Last enriched: 10/09/2026, 22:46:53 UTC
Last updated: 10/09/2026, 22:46:53 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.