Cotonti

12 known vulnerabilities in Cotonti, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-101093 CVSS 5.3 medium Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups…
  • CVE-2026-100524 CVSS 5.3 medium Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform…
  • CVE-2026-100523 CVSS 5.1 medium Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain…
  • CVE-2026-100522 CVSS 5.1 medium Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly…
  • CVE-2026-100521 CVSS 5.1 medium Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no…
  • CVE-2026-93873 CVSS 5.3 medium Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages…
  • CVE-2026-93872 CVSS 7.7 high Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin…
  • CVE-2026-93871 CVSS 5.1 medium Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page…
  • CVE-2026-93870 CVSS 5.3 medium Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf…
  • CVE-2026-93869 CVSS 5.3 medium Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a…
  • CVE-2026-93868 CVSS 9.2 critical Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable…
  • CVE-2026-91939 CVSS 9.3 critical Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated…