by Leo Feyer
Cross-site scripting in the comments bundle
Date: 2026-08-25
CVE ID: CVE-2026-XXXXX
Description
Unauthenticated users can inject code into frontend comments that is then executed in the backend.
Affected versions
Contao 4.0
Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11
Suggested solution
Upgrade to Contao 5.3.50 or 5.7.12.
Workaround
Disable comments in the frontend.
More information
https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r