Skip to content
feed: live
0dayNews
threat intel

Contao Patches Critical XSS in Four-CVE Update

Contao 5.3.50 and 5.7.12 fix a critical stored XSS in the comment module that executes in admin sessions, plus three medium-severity issues. Update now.

Contao Patches Critical XSS in Four-CVE Update
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·2 min read

Contao’s comment form writes the email address and website URL a visitor provides into rendered page output. Before versions 5.3.50 and 5.7.12, those values reached the template without adequate attribute or HTML-context escaping. CVE-2026-107845 (CVSS 9.3, critical) is the result: any unauthenticated visitor can submit a comment with a payload in the email or website field and get persistent JavaScript into the moderation queue. An administrator who opens that queue runs it.

The three remaining CVEs in the same release each score CVSS 5.3.

Path traversal in image handling

CVE-2026-107844 is in ImagesController. The controller builds output paths by joining a user-controlled {path} parameter to the configured image directory using Path::join(). That join does not fully strip directory-traversal sequences, so a crafted value can reach outside the intended image directory. The scope is bounded by the image target directory and its parent structure, but the sanitization is incomplete. Affects versions 5.0.0 through 5.3.49 and 5.7.11; the path is missing from the 4.x line.

Search module surfaces protected content

CVE-2026-107842 is in ModuleSearch. Unauthenticated visitors can receive page titles, URLs, and indexed content snippets for pages that Contao’s access control marks as protected. The pages themselves remain blocked. Only metadata and context excerpts surface, but that is enough to reveal a site’s structure and draft or restricted content to anyone who runs a search query.

Registration module acts on bare POST submissions

CVE-2026-107843 is in ModuleRegistration. The module enters its post-registration logic on any POST to a page containing the registration module, regardless of whether a user completed the registration form. A crafted POST to that page triggers the follow-up branch without valid prior input. The practical impact depends on what a site’s post-registration logic does.

Affected versions and fixes

The critical XSS (CVE-2026-107845), the search disclosure (CVE-2026-107842), and the registration bypass (CVE-2026-107843) all affect Contao versions from 4.0.0 through 5.3.49 and 5.7.11. The path-traversal issue starts at 5.0.0. All four are resolved in 5.3.50 and 5.7.12.

Update to 5.3.50 or 5.7.12. The comment module containing CVE-2026-107845 is enabled on most installs by default. If your update window is not immediate, disable public comment submission on any publicly reachable page until the patch is applied.

For related web-platform patching this week, see the WooCommerce plugin roundup and last week’s four CVSS 9.8 WordPress auth bypass flaws. The threat intel hub tracks ongoing coverage.

Found this useful? Share it.