Skip to main content

Contao: Cross-site scripting in the comments bundle (CVE-2026-107845)

0
Critical
Published: 10/09/2026 (10/09/2026, 20:53:50 UTC)
Source: GCVE Database
Product: contao/comments-bundle

Description

CVE-2026-107845 is a critical cross-site scripting (XSS) vulnerability in the Contao comments bundle that allows unauthenticated front end visitors to inject malicious scripts in comments. These scripts execute in the context of any back end user who opens the Comments module, without requiring any user interaction. The lack of a Content-Security-Policy header on the Contao back end allows inline script execution. This can lead to full back end compromise, including reading modules, creating administrators, or editing templates that enable code execution. Moderation does not prevent exposure and actually guarantees it since unpublished comments are still loaded by moderators. A patch is available for affected versions.

CVSS v3.1

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected software

Packagistghsa
contao/comments-bundle
Affected versions
>=4.0.0 <5.3.50
Packagistghsa
contao/comments-bundle
Affected versions
>=5.4.0-RC1 <5.7.12

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 22:46:53 UTC

Technical Analysis

The Contao comments bundle contains a stored cross-site scripting vulnerability (CVE-2026-107845) that permits an unauthenticated visitor to submit a comment with malicious script code. When a back end user opens the Comments module, the injected script executes automatically in their session context due to the absence of Content-Security-Policy headers. This allows the attacker to perform actions with the privileges of the back end user, including reading accessible modules, creating new administrators, or modifying templates that can lead to remote code execution. Moderation does not mitigate the issue because unpublished comments are still rendered, ensuring exposure. The vulnerability affects Contao versions >=4.0.0 <5.3.50 and >=5.4.0-RC1 <5.7.12. A patch is available to remediate this critical security flaw.

Potential Impact

An attacker can inject malicious scripts via comments that execute in the browser of any back end user who views the Comments module, without requiring any interaction. This results in full compromise of the back end user session, allowing the attacker to read data, create new administrators, or modify templates to achieve code execution. The vulnerability effectively allows remote code execution through the back end interface. Moderation does not prevent exploitation and actually ensures exposure of the malicious payload to back end users.

Mitigation Recommendations

A patch is available for this vulnerability and should be applied promptly. Since the vulnerability is in the Contao comments bundle and affects specific versions, upgrading to a fixed version is the recommended remediation. There is no indication that Content-Security-Policy headers are currently implemented, so relying on such mitigations is insufficient. Moderation does not prevent exploitation and should not be relied upon as a mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-628f-v4f6-p37r
Osv Schema Version
1.4.0
Aliases
["CVE-2026-107845"]
Ecosystems
["Packagist"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6ac96e432cdf04f65689a682

Added to database: 10/09/2026, 22:44:19 UTC

Last enriched: 10/09/2026, 22:46:53 UTC

Last updated: 10/09/2026, 22:46:53 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses