by Leo Feyer

Cross-site scripting in the comments bundle

Date: 2026-08-25
CVE ID: CVE-2026-XXXXX

Description

Unauthenticated users can inject code into frontend comments that is then executed in the backend.

Affected versions

Contao 4.0
Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13
Contao 5.0
Contao 5.1
Contao 5.2
Contao 5.3 up to 5.3.49
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.11

Suggested solution

Upgrade to Contao 5.3.50 or 5.7.12.

Workaround

Disable comments in the frontend.

More information

https://github.com/contao/contao/security/advisories/GHSA-628f-v4f6-p37r