CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107845

CRITICALCVSS 9.3NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user ope

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107845 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107845

CRITICALCVSS 9.3NVD feed

Published 9 October 2026 · tracked since 10 October 2026

Description

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user ope

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]