CVE-2026-101093: medium-severity vulnerability in Cotonti
Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
Cotonti · CotontiRelated CVEs — Cotonti
In the same product, most dangerous first.
CVE-2026-91939CRITICALCotonti 1.0.0 Comments Plugin PHP Object Injection via ci ParameterEPSS 1.0%CVE-2026-93868CRITICALCotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNGEPSS 0.7%CVE-2026-93872HIGHCotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb ParameterEPSS 0.7%CVE-2026-71294HIGHCotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit ActionsEPSS 0.4%CVE-2026-93869MEDIUMCotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() RegexEPSS 0.4%CVE-2026-55746HIGHCotonti stored XSS via PFS folder titleEPSS 0.3%
References
https://github.com/Cotonti/Cotontihttps://github.com/Cotonti/Cotonti/blob/1.0.0/system/admin/admin.users.php#L136-L140https://github.com/Cotonti/Cotonti/issues/1907#issuecomment-5845691148https://github.com/Cotonti/Cotonti/pull/1908https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-via-user-group-deletion