Skip to content
eastbaycyber

CVE-2026-107845: Contao Stored XSS

CVSS · Critical
9.3
In CISA KEV
No
Published
Oct 9
CVE explainers 9 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-09
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2026-107845 is a critical stored cross-site scripting vulnerability in Contao’s Comments module. - Unauthenticated attackers can submit malicious email or website metadata that executes when a moderator opens Comments. - Upgrade to Contao 5.3.50 or 5.7.12, and restrict public comments until remediation is complete.

Vulnerability at a Glance

Field Details
CVE ID CVE-2026-107845
Product Contao Open Source CMS
CVSS score 9.3, Critical
Attack vector Network-based through public comment submission
Authentication required No for comment submission
User interaction A backend user must open the Comments module
Vulnerability type Stored cross-site scripting caused by insufficient output encoding
Patch available Yes
Fixed versions Contao 5.3.50 and 5.7.12
CISA KEV status Not listed; on_kev: false

CVE-2026-107845 allows an unauthenticated visitor to place attacker-controlled data into a comment. The vulnerable data includes email and website metadata, which can later be rendered in the Contao backend without adequate attribute or URL encoding. The resulting script executes under the origin of the Contao administration interface.

Unpublished comments remain visible to users who moderate comments. As a result, a comment does not need to be approved or publicly displayed for an attacker-controlled payload to reach a backend user.

Sites with public comments enabled and frequent moderation activity should prioritize remediation.

Analyst’s Take: Stop new untrusted submissions first, then patch the Contao branch in use. Because ordinary comment review is the key exposure point, existing comments should be treated as potentially unsafe until they have been reviewed.

What Is CVE-2026-107845?

The root cause is improper contextual output encoding in the listComments() function located at:

comments-bundle/contao/dca/tl_comments.php

According to the vulnerability description, attacker-controlled email and website values are rendered into HTML attributes or URLs without sufficient encoding. A value that is harmless as plain text can become executable when inserted into an HTML or URL context.

Stored XSS differs from reflected XSS because the malicious input is persisted and delivered later to another user through a normal application workflow. In this case, the workflow is backend comment moderation.

The execution context is especially sensitive because the victim is a Contao backend user. Depending on the victim’s permissions and the application’s session protections, successful exploitation could enable:

  • Unauthorized administrative actions
  • Content modification
  • Configuration changes
  • Misuse of information available to the victim’s session

The vulnerability does not automatically grant every attacker full server access. The likely impact depends on the privileges of the backend user who opens the Comments module.

Technical Details

The affected code path is associated with the following function and file:

Function: listComments()
Path: comments-bundle/contao/dca/tl_comments.php
Data: Comment email and website metadata
Sink: Backend Comments module rendering

Untrusted values rendered in an HTML attribute or URL require context-sensitive encoding. Generic HTML escaping may not be sufficient for every URL or JavaScript-adjacent context. Upgrading to the upstream fixed release is preferable to attempting a local template change.

AnalystImpact · assess the risk

Who Is Affected?

The affected Contao versions are:

  • Contao 4.0.0 through 5.3.49
  • Contao 5.4.x
  • Contao 5.5.x
  • Contao 5.6.x
  • Contao 5.7.0 through 5.7.11

The corrected releases are:

  • Contao 5.3.50
  • Contao 5.7.12

Verify the exact installed version and dependency lockfile. A deployment may contain multiple Contao packages or branch-specific dependency resolutions that are not obvious from the application’s displayed version.

Sites face the most direct exposure when:

  1. Anonymous visitors can submit comments.
  2. Email or website metadata is accepted with a comment.
  3. Staff members review those comments through the Contao backend.

A site with comments disabled may not currently expose the vulnerable submission path, but it should still be upgraded. Configuration can change, and other routes may depend on the same bundle. Managed hosting customers should confirm both the application version and the release branch used by their provider.

CVSS Score Breakdown

CVE-2026-107845 has a reported CVSS base score of 9.3, categorized as Critical. The available record does not include the complete CVSS vector, so individual metric values cannot be independently verified or responsibly reconstructed.

The precise values for attack complexity, privileges required, user interaction, scope, confidentiality, integrity, and availability are not provided in the supplied vulnerability record.

The practical risk is nevertheless significant:

  • The initial submission does not require authentication.
  • The attack is performed remotely through the public application.
  • The payload reaches a privileged administrative workflow.
  • Opening Comments is a normal moderation task, not an unusual security action.

For background on vulnerability scoring, see the difference between CVE and CVSS.

Use the published score to guide prioritization, then apply your organization’s exposure and privilege model to assess likely impact.

Technical Notes

Do not create a replacement CVSS vector from assumptions. Track the published score and record the missing vector as an evidence gap:

CVE: CVE-2026-107845
Base score: 9.3
Vector: Not included in the available NVD record
Authentication for submission: Not required
Required victim action: Backend user opens Comments

If a later vendor, NVD, or CNA update publishes the vector, update internal risk records and scanner exceptions.

Exploitation Status

CVE-2026-107845 is not listed in the CISA Known Exploited Vulnerabilities catalog. The checked status is on_kev: false. Therefore, there is currently no CISA-assigned date, remediation deadline, required action, or ransomware-campaign designation for this CVE.

This does not prove that exploitation has never occurred. It means only that CISA KEV does not currently provide that confirmation.

A dedicated public exploit or proof-of-concept repository is not identified in the available record. The available references include an upstream fix commit, release pages, and a GitHub security advisory, but those references should not be confused with a public exploit.

Based on the supplied evidence:

  • Confirmed active exploitation in the wild is not known.
  • A public proof of concept is not known.
  • The absence of a PoC or KEV listing should not delay patching.

The attack begins with an unauthenticated comment submission and targets an administrative origin, making timely remediation important even without confirmed exploitation.

ResponderRunbook · act now

How to Detect CVE-2026-107845

Detection should combine:

  • Application inventory
  • Comment-content review
  • Web access logs
  • Backend activity
  • Contao and reverse-proxy telemetry

First, identify Contao installations on vulnerable branches. Then determine whether public comments are enabled and which accounts access the Comments module.

Review existing comments for:

  • Suspicious markup
  • Event-handler syntax
  • Malformed attributes
  • Unusual URL schemes
  • Encoded script indicators
  • Unexpected content in email or website fields

Web server logs may show anonymous requests to the comment submission endpoint. The exact URI and parameter names depend on the Contao configuration and deployment, so do not rely on one universal path.

Use application routing and a known-good submission to identify the local endpoint. Then search historical traffic for anomalous submissions and correlate them with later backend access.

Detection Examples

The following searches are starting points, not vendor-specific signatures. Adjust the log path, field names, and URL encoding for the deployment:

# Search access logs for common XSS indicators, including URL-encoded forms
grep -Ei '(<script|%3cscript|javascript:|%3ajavascript|onerror=|%6fnerror|onload=|%6fnload)' \
  /var/log/nginx/access.log /var/log/apache2/access.log

For structured logs in a SIEM, correlate suspicious comment submissions with later backend access:

event.category:web
AND http.request.method:POST
AND url.path:*comment*
AND (
  url.query:"<script" OR
  url.query:"javascript:" OR
  url.query:"onerror=" OR
  url.query:"onload="
)

Review Contao and reverse-proxy logs for successful backend requests to the Comments module after suspicious submissions. Examine audit trails for:

  • Unexpected content edits
  • User changes
  • Configuration updates
  • New administrative accounts
  • Other actions performed by moderator accounts

A lack of suspicious log entries does not prove that no payload was stored. Logging may omit request bodies, and older records may have been rotated.

Mitigation and Patching

Upgrade affected Contao installations to 5.3.50 or 5.7.12, selecting the release appropriate to the supported application branch.

Before deployment:

  1. Back up the application and database.
  2. Test the update in a staging environment.
  3. Deploy the dependency lockfile with the application.
  4. Verify the installed package versions.
  5. Confirm that the Comments module and other extensions function correctly.

For Composer-managed installations, the exact command depends on the project’s declared Contao branch and dependency constraints. A typical branch-specific update is:

# For projects pinned to the Contao 5.3 maintenance branch
composer require contao/manager-bundle:^5.3 --with-all-dependencies

# For projects using the Contao 5.7 maintenance branch
composer require contao/manager-bundle:^5.7 --with-all-dependencies

# Confirm the resolved installed version
composer show contao/manager-bundle contao/comments-bundle

Do not run a blind major-version upgrade in production. Confirm that the lockfile resolves to:

  • 5.3.50 or later within the 5.3 branch, or
  • 5.7.12 or later within the 5.7 branch

Subject to Contao’s supported release policy and the project’s dependency constraints, use the hosting control panel or deployment process appropriate to your environment while verifying the final installed package versions.

Temporary Mitigations

Until patching is complete, apply layered controls:

1. Disable public comments or require authenticated submission.
2. Restrict or remove untrusted email and website metadata where feasible.
3. Limit backend access to trusted administrators and moderators.
4. Use a temporary WAF rule to block obvious script and dangerous URL patterns.
5. Review existing comments before moderators open the Comments module.
6. Monitor moderator sessions and administrative changes.

A web application firewall can provide temporary defense in depth; learn more in What is a web application firewall?. However, generic XSS filtering is not a replacement for patching. Encoding bypasses, alternate representations, and legitimate application behavior can make filtering incomplete.

After upgrading:

  • Inspect stored comments.
  • Review backend activity during the vulnerable exposure period.
  • Investigate suspicious administrative actions.
  • Rotate relevant credentials and session material if compromise is suspected.
  • Follow the organization’s incident-response procedures.

If incident response requires resetting shared administrative credentials, a password manager such as Try 1Password → can help teams generate and manage unique replacement credentials.

References

The primary vulnerability record is the NVD entry for CVE-2026-107845:

Upstream remediation and release information:

Exploitation-status verification and prioritization:

As of the reviewed information, CISA KEV does not list CVE-2026-107845, and no dedicated public PoC is identified. Continue monitoring the upstream advisory, NVD record, and local telemetry for changes.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-10-09

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.