Critical severity9.8NVD Advisory· Published Sep 15, 2026
CVE-2026-91939
CVE-2026-91939
Description
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/Cotonti/Cotonti/blob/1.0.0/plugins/comments/comments.setup.phpnvd
- github.com/Cotonti/Cotonti/blob/1.0.0/plugins/comments/controllers/actions/DisplayAction.phpnvd
- github.com/Cotonti/Cotonti/blob/1.0.0/plugins/comments/inc/CommentsWidget.phpnvd
- github.com/Cotonti/Cotonti/issues/1888nvd
- github.com/Cotonti/Cotonti/pull/1889nvd
- www.vulncheck.com/advisories/cotonti-1.0.0-comments-plugin-php-object-injection-via-ci-parameternvd
News mentions
0No linked articles in our index yet.