Medium · 5.7 PHP packages GHSA-628f-v4f6-p37r CVE-2026-107845 PKSA-c42s-m9fj-8jxw
CVE-2026-107845 — XSS in contao/comments-bundle exposes backend when moderators view comments
The contao/comments-bundle contains a stored cross-site scripting flaw that allows an unauthenticated visitor to submit a comment whose email or website metadata is rendered without proper attribute/URL encoding. When a backend user opens the Comments module, attacker-controlled script can run in the Contao backend origin under that user's session. Fixed in updates supplied by the vendor. (Identifiers: CVE-2026-107845, GHSA-628f-v4f6-p37r, PKSA-c42s-m9fj-8jxw.)
AI summary
A stored cross-site scripting defect in contao/comments-bundle can cause attacker-controlled script to execute in the Contao backend origin when a backend user opens the Comments module. The issue is tracked as CVE-2026-107845 and also published as GHSA-628f-v4f6-p37r. The vendor published fixes; administrators should plan updates. (Sources: 3969, 4164, 8436, 32347.)
What happened
An unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, that attacker-controlled script can execute in the Contao backend origin under the backend user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. (Sources: 3969, 8436, 4164, 32347.)
Technical cause
listComments() in comments-bundle/contao/dca/tl_comments.php renders comment email or website metadata without adequate attribute and URL encoding, resulting in a stored cross-site scripting (CWE-79) vulnerability. (Sources: 3969, 8436, 4164.)
Why it matters
The flaw permits attacker-controlled script to run within the Contao backend origin when a backend user views the Comments module. The published CVSS v3.1 score is 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), indicating a high-severity remote vulnerability with high confidentiality and integrity impact when triggered. (Sources: 32347, 3969, 8436.)
Who is affected
The vulnerability affects contao/comments-bundle. Affected ranges reported are 4.0.0 up to but not including 5.3.50, and 5.4.0-RC1 up to but not including 5.7.12 (expressed in sources as >=4.0.0,<5.3.50 and >=5.4.0-RC1,<5.7.12). (Sources: 3969, 4164, 8436.)
Discovery and timeline
The vulnerability was published on 2026-10-09 (advisories and database entries published 2026-10-09). No discoverer attribution is provided in the available sources. (Sources: 3969, 4164, 8436, 32347.)
Affected and fixed versions
Sources report fixed releases for contao/comments-bundle: 5.3.50 and 5.7.12. Affected ranges are given as >=4.0.0,<5.3.50 and >=5.4.0-RC1,<5.7.12. (Sources: 3969, 4164, 8436.)
Fixes and mitigation
Vendor fixes are available: the issue is fixed in contao/comments-bundle releases 5.3.50 and 5.7.12. The advisory notes that moderation alone does not prevent exposure because unpublished comments are visible to moderators. No additional vendor mitigations are listed in the sources. (Sources: 3969, 8436, 4164.)
Recommended action
Apply the vendor updates to contao/comments-bundle to a fixed release (5.3.50 or 5.7.12 as published). If you cannot immediately update, consider restricting access to the backend Comments module until you can apply the update and review comments for malicious content. Verify that comment metadata is properly encoded in any custom integrations. (Sources: 3969, 8436, 4164.)
PatchBriefing score
5.7 / 10 · Medium
Official CVSS: 9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Why this score
PatchWire score 5.7. This score uses the published CVSS base score of 9.3 (contribution 5.12) plus adjustments: the issue is unauthenticated and remote (unauthenticated_remote contribution 0.6). No known exploitation or public exploit contributions were reported; no EPS/EPSS contribution is present. The combined factors yield the PatchWire score of 5.7. (Sources: 3969, 32347.)
Affected versions
- contao/comments-bundle ≥ 5.4.0-RC1 < 5.7.12
- vulnerable
- contao/comments-bundle
- vulnerable
- contao/comments-bundle >=5.4.0-RC1,<5.7.12|>=4.0.0,<5.3.50
- vulnerable
- contao/comments-bundle >= 5.4.0-RC1, < 5.7.12
- vulnerable
- ≥ 5.3.50
- patched
- ≥ 5.7.12
- patched
Reported fixes
Vendor fixes are available: the issue is fixed in contao/comments-bundle releases 5.3.50 and 5.7.12. The advisory notes that moderation alone does not prevent exposure because unpublished comments are visible to moderators. No additional vendor mitigations are listed in the sources. (Sources: 3969, 8436, 4164.)
How this was built
4 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
Packagist Security Advisories registry
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email