CVE-2026-107848 | Contao up to 5.3.49/5.7.11 Request Token Validation RequestTokenListener act/key cross-site request forgery
A vulnerability, which was classified as problematic, has been found in Contao up to 5.3.49/5.7.11. This affects the function RequestTokenListener of the component Request Token Validation. This manipulation of the argument act/key causes cross-site request forgery.
This vulnerability is handled as CVE-2026-107848. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More