CVE-2026-107845 - Contao: Cross-site scripting in the comments bundle
CVE ID :CVE-2026-107845 Published : Oct. 9, 2026, 8:17 p.m. | 1 hour, 12 minutes ago Description :Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute...