CVE-2026-107845 | Contao up to 5.3.49/5.7.11 Comments module tl_comments.php listComments cross site scripting

SecurityVulns

A vulnerability was found in Contao up to 5.3.49/5.7.11. It has been classified as problematic. This vulnerability affects the function listComments of the file comments-bundle/contao/dca/tl_comments.php of the component Comments module. Performing a manipulation results in cross site scripting.

This vulnerability is identified as CVE-2026-107845. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More