Cotonti
Products
2- 26 CVEs
- 0 CVEs
Recent CVEs
25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-55742 | Cri | 0.62 | 9.6 | 0.00 | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_group) without… | ||
| CVE-2026-91939 | Cri | 0.57 | 9.8 | 0.01 | Sep 15, 2026 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted… | ||
| CVE-2026-55741 | Hig | 0.57 | 8.8 | 0.00 | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via cot_config_update_options without… | ||
| CVE-2026-55744 | Hig | 0.53 | 8.1 | 0.00 | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes uploaded files without calling cot_check_xg to validate the… | ||
| CVE-2026-71294 | Hig | 0.49 | 7.6 | 0.00 | Aug 5, 2026 | Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by… | ||
| CVE-2026-55746 | Hig | 0.49 | 7.6 | 0.00 | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so… | ||
| CVE-2026-93868 | Hig | 0.46 | 8.1 | 0.01 | Sep 18, 2026 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate… | ||
| CVE-2026-93872 | Hig | 0.42 | 7.5 | 0.01 | Sep 18, 2026 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution… | ||
| CVE-2026-55745 | Med | 0.35 | 5.4 | 0.00 | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags)… | ||
| CVE-2021-47808 | Med | 0.35 | 5.4 | 0.00 | Jan 16, 2026 | Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page. | ||
| CVE-2025-44115 | Med | 0.35 | 5.4 | 0.00 | Jun 2, 2025 | A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting. | ||
| CVE-2024-24115 | Med | 0.35 | 5.4 | 0.00 | Feb 8, 2024 | A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2026-100523 | Med | 0.33 | 6.1 | 0.00 | Sep 26, 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh… | ||
| CVE-2026-100522 | Med | 0.33 | 6.1 | 0.00 | Sep 26, 2026 | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to… | ||
| CVE-2026-100521 | Med | 0.33 | 6.1 | 0.00 | Sep 26, 2026 | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the… | ||
| CVE-2026-93869 | Med | 0.33 | 6.1 | 0.00 | Sep 18, 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site… | ||
| CVE-2022-39840 | Med | 0.31 | 4.8 | 0.00 | Sep 5, 2022 | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM). | ||
| CVE-2022-39839 | Med | 0.31 | 4.8 | 0.00 | Sep 5, 2022 | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post. | ||
| CVE-2026-100524 | Med | 0.28 | 5.4 | 0.00 | Sep 26, 2026 | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links or embed images to force administrators to install, update,… | ||
| CVE-2026-93871 | Med | 0.28 | 5.4 | 0.00 | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect… |
- risk 0.62cvss 9.6epss 0.00
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_group) without…
- risk 0.57cvss 9.8epss 0.01
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted…
- risk 0.57cvss 8.8epss 0.00
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via cot_config_update_options without…
- risk 0.53cvss 8.1epss 0.00
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes uploaded files without calling cot_check_xg to validate the…
- risk 0.49cvss 7.6epss 0.00
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by…
- risk 0.49cvss 7.6epss 0.00
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so…
- risk 0.46cvss 8.1epss 0.01
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate…
- risk 0.42cvss 7.5epss 0.01
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution…
- risk 0.35cvss 5.4epss 0.00
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags)…
- risk 0.35cvss 5.4epss 0.00
Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.
- risk 0.35cvss 5.4epss 0.00
A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.33cvss 6.1epss 0.00
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh…
- risk 0.33cvss 6.1epss 0.00
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to…
- risk 0.33cvss 6.1epss 0.00
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the…
- risk 0.33cvss 6.1epss 0.00
Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site…
- risk 0.31cvss 4.8epss 0.00
Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).
- risk 0.31cvss 4.8epss 0.00
Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.
- risk 0.28cvss 5.4epss 0.00
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links or embed images to force administrators to install, update,…
- risk 0.28cvss 5.4epss 0.00
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect…