High severity7.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93872
CVE-2026-93872
Description
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.
Patches
Vulnerability mechanics
References
5- github.com/Cotonti/Cotonti/blob/1.0.0/plugins/comments/controllers/actions/EditAction.phpnvd
- github.com/Cotonti/Cotonti/blob/1.0.0/system/cache.phpnvd
- github.com/Cotonti/Cotonti/issues/1894nvd
- github.com/Cotonti/Cotonti/pull/1897nvd
- www.vulncheck.com/advisories/cotonti-1.0.0-php-object-injection-via-comments-plugin-edit-action-cb-parameternvd
News mentions
0No linked articles in our index yet.