---
id: CVE-2026-93871
title: >-
  Cotonti through 1.0.0 fails to validate redirect destinations in page bodies
  prefixed with redir:, allowing authenticated users with page creation or edit
  permissions to store redirects to arbitrary external hosts
summary: >-
  Cotonti through 1.0.0 fails to validate redirect destinations in page bodies
  prefixed with redir:, allowing authenticated users with page creation or edit
  permissions to store redirects to arbitrary external hosts. Attackers can
  craft pa…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: Cotonti
product: Cotonti
affected:
  - Cotonti <= 1.0.0
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:53:07.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93871'
references:
  - url: 'https://github.com/Cotonti/Cotonti'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Cotonti/Cotonti/blob/1.0.0/modules/page/inc/page.main.php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Cotonti/Cotonti/issues/1893'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Cotonti/Cotonti/pull/1901'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cotonti-through-1.0.0-stored-open-redirect-via-page-redir-prefix
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00274
epssPercentile: 0.17559
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T16:33:05.806544Z'
ingestedAt: '2026-09-18T20:51:25.689Z'
---

## Overview

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
