CPE
An unauthenticated stored XSS vulnerability in the Contao comments-bundle allows remote attackers to execute arbitrary JavaScript in the context of administrative sessions, potentially leading to full system compromise.