External risk intelligence

Contao Backend Cross-Site Scripting via Unencoded Comment Metadata

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-107845

Contao is a web-based content management system commonly deployed as a public-facing web application. While this specific vulnerability requires an administrative user to view the malicious content in the backend, the attack vector originates from a public-facing comment submission form, which is a standard, internet-exposed feature of such applications.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Contao content management system. This issue allows an unauthenticated visitor to submit specially crafted comments that, when viewed by a backend user, can lead to the execution of malicious scripts within the Contao backend. While this requires a backend user to view the comments, the vulnerability stems from a publicly accessible feature.

  • Website comments can run harmful code in the backend.
  • This impacts backend user sessions if comments are viewed.
  • Confirm if your Contao instances are affected and need updates.

Attack Path

How an attacker could exploit the issue

An attacker can submit a comment with specially crafted email or website metadata. When a Contao administrator views these comments in the backend, the malicious script embedded in the metadata can execute within their browser, potentially leading to the compromise of the administrator's session and the Contao backend.

  • Unauthenticated visitors can submit comments.
  • Administrator views comments in backend module.
  • Backend account takeover or malicious actions.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated visitor could submit a crafted comment that, when viewed by a backend user in the Comments module, executes attacker-controlled script within the user's session. This could affect the confidentiality and integrity of the Contao backend for users who moderate comments.

  • Contao backend user sessions could be compromised.
  • Malicious scripts execute when viewing comments.
  • Backend data integrity and confidentiality may be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

Infrastructure and platform teams likely own the Contao CMS instances. The immediate first step is to inventory all Contao deployments, determine their exposure and criticality, identify the specific application owners, and then prioritize remediation efforts.

  • Identify all Contao instances.
  • Verify administrator access and network exposure.
  • Plan updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Contao?

Contao is an open-source content management system (CMS) designed to help users build and manage professional websites. It includes built-in features for managing web content, including a module that handles user-submitted comments on public-facing pages, which allows site owners to interact with their visitors.

What does CWE-79 mean for CVE-2026-107845?

CWE-79 is a weakness class known as Cross-Site Scripting (XSS). In this specific case, the software fails to properly encode user-supplied metadata—like email addresses or website URLs—before displaying them. This allows an attacker to inject malicious scripts into the data, which the web browser then executes as if it were legitimate code from the site.

How does an attacker trigger this vulnerability?

An attacker triggers this by submitting a comment containing crafted script code through a public-facing comment form. The bug is only activated when an administrator views the submission within the Contao backend. Simply submitting a comment from a guest account does not trigger the script execution itself; the action of an authorized user loading the comments module is required.

Is my site at risk?

If you run an affected version of Contao with public commenting enabled, your installation is potentially at risk. According to Halo Surface Signal, because this CMS is typically deployed as a public-facing application, the comment submission point is accessible to anyone on the internet, creating a clear path for malicious input to reach your backend moderators.

How should I respond to this vulnerability?

The primary response is to update your Contao installation to version 5.3.50 or 5.7.12, where this encoding issue has been resolved. Start by creating an inventory of all your Contao instances to identify which ones are running vulnerable versions, then coordinate with your team to schedule and apply the necessary updates during your next maintenance window.

References