Medium severity6.1NVD Advisory· Published Sep 26, 2026· Updated Sep 26, 2026
CVE-2026-100521
CVE-2026-100521
Description
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the browser of any visitor who opens the link, including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/Cotonti/Cotonti/blob/1.0.0/plugins/search/search.header.phpnvd
- github.com/Cotonti/Cotonti/blob/1.0.0/plugins/search/search.page.first.phpnvd
- github.com/Cotonti/Cotonti/issues/1907nvd
- github.com/Cotonti/Cotonti/pull/1908nvd
- www.vulncheck.com/advisories/cotonti-through-1.0.0-reflected-xss-via-search-highlight-parameternvd
News mentions
0No linked articles in our index yet.