Vulnerabilities in Cotonti
19 resultsVexday analysis
Cotonti apresenta 8 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descobertas recentes concentradas em um curto período. Embora nenhuma esteja sob exploração ativa documentada, a presença de 1 vulnerabilidade crítica e a dominância de falhas de validação de tokens (CWE-352) exigem atenção imediata para mitigação. O risco é elevado pela recência das descobertas e severidade potencial, apesar da ausência atual de exploração em campo.
CVE-2026-91939CRITICALCotonti 1.0.0 Comments Plugin PHP Object Injection via ci ParameterEPSS 1.0%CVE-2026-93868CRITICALCotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNGEPSS 0.7%CVE-2026-93872HIGHCotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb ParameterEPSS 0.7%CVE-2026-71294HIGHCotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit ActionsEPSS 0.4%CVE-2026-93869MEDIUMCotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() RegexEPSS 0.4%CVE-2026-55746HIGHCotonti stored XSS via PFS folder titleEPSS 0.3%CVE-2026-93871MEDIUMCotonti through 1.0.0 Stored Open Redirect via Page redir: PrefixEPSS 0.3%CVE-2026-58143HIGHCotonti Siena 0.9.26 CSRF via admin.php Config Update EndpointEPSS 0.2%CVE-2026-58144MEDIUMCotonti Siena 0.9.26 Stored XSS via PFS Module ntitle ParameterEPSS 0.2%CVE-2026-100522MEDIUMCotonti through 1.0.0 Reflected XSS via message.php lng parameterEPSS 0.2%CVE-2026-55741HIGHCotonti CSRF in admin.config.php allows unauthorized configuration changesEPSS 0.2%CVE-2026-55742CRITICALCotonti CSRF in admin.rights.php allows privilege escalationEPSS 0.2%CVE-2026-100521MEDIUMCotonti through 1.0.0 Reflected XSS via search highlight parameterEPSS 0.2%CVE-2026-55744HIGHCotonti CSRF in PFS allows forced arbitrary file uploadEPSS 0.2%CVE-2026-93873MEDIUMCotonti through 1.0.0 Cross-Site Request Forgery in the Contact PluginEPSS 0.2%CVE-2026-93870MEDIUMCotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX HandlerEPSS 0.2%CVE-2026-100523MEDIUMCotonti through 1.0.0 Open Redirect via message.php redirect parameterEPSS 0.2%CVE-2026-55745MEDIUMCotonti CSRF in PFS folder edit allows unauthorized folder modificationEPSS 0.1%CVE-2026-100524MEDIUMCotonti through 1.0.0 Cross-Site Request Forgery via Extensions ManagerEPSS 0.1%