CVE-2026-107843: Contao

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.

Affected products

  • Contao Contao: from 4.1.0, before 5.3.50 (fixed in 5.3.50); from 5.4.0-RC1, before 5.7.12 (fixed in 5.7.12)

Published 2026-10-09. Last modified 2026-10-09.