{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acontaocomments_bundle/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:contao:comments_bundle:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-107845"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["comments-bundle (4.0.0 \u003c= v \u003c 5.3.50)","comments-bundle (5.4.0-RC1 \u003c= v \u003c 5.7.12)"],"_cs_severities":["critical"],"_cs_tags":["web-application","xss","cve"],"_cs_type":"advisory","_cs_vendors":["Contao"],"content_html":"\u003cp\u003eThe Contao comments-bundle is vulnerable to stored cross-site scripting (XSS) due to improper input sanitization in the front-end comment submission mechanism. Tracked as CVE-2026-107845, this vulnerability allows unauthenticated attackers to submit comments containing malicious payloads that persist within the application database. When an administrator or moderator accesses the back-end Comments module to review pending submissions, the injected script executes automatically within their browser session.\u003c/p\u003e\n\u003cp\u003eBecause the Contao back-end lacks a robust Content-Security-Policy (CSP), the payload can perform any action available to the authenticated administrator, including modifying system templates, creating new administrative accounts, or exfiltrating session tokens. The design of the module ensures that moderation activity triggers the vulnerability, making it highly effective for attackers seeking to target administrative users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a critical risk to Contao installations, enabling unauthenticated remote attackers to gain administrative control over the application. Successful exploitation leads to full application compromise, as the attacker can leverage the administrative interface to inject malicious code into templates, resulting in server-side remote code execution. The scope of impact includes any Contao instance using the vulnerable versions of the comments-bundle, with no user interaction required beyond an administrator accessing the moderation interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Contao comments-bundle to version 5.3.50 or later, or 5.7.12 or later, to incorporate necessary input sanitization.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content-Security-Policy (CSP) on the back-end to mitigate the impact of potential XSS vulnerabilities until all components are updated.\u003c/li\u003e\n\u003cli\u003eAudit administrative logs for unexpected account creation or template modifications occurring in proximity to comment moderation activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T21:23:18Z","date_published":"2026-10-09T21:23:18Z","id":"https://feed.craftedsignal.io/briefs/2026-10-contao-xss/","summary":"An unauthenticated stored XSS vulnerability in the Contao comments-bundle allows remote attackers to execute arbitrary JavaScript in the context of administrative sessions, potentially leading to full system compromise.","title":"Stored Cross-Site Scripting in Contao Comments Bundle","url":"https://feed.craftedsignal.io/briefs/2026-10-contao-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:contao:comments_bundle:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}