contao/comments-bundle Security Advisories for 4.5.13 (3)
-
[CRITICAL] Contao: Cross-site scripting in the comments bundle
PKSA-c42s-m9fj-8jxw CVE-2026-107845 GHSA-628f-v4f6-p37r
Affected version: >=5.4.0-RC1,<5.7.12|>=4.0.0,<5.3.50
Reported by:
GitHub -
Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)
Affected version: >=4.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] Contao: Insufficient BBCode sanitizer
PKSA-38dw-gzd8-gz6c CVE-2024-28234 GHSA-j55w-hjpj-825g
Affected version: >=5.0.0-RC1,<5.3.4|>=2.0.0,<4.13.40
Reported by:
GitHub