cotonti/cotonti vulnerabilities
CVEs whose affected-version data names the cotonti/cotonti package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-55744High· 8.1Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
▾ Twilightcotonti · cotonti/cotontiEPSS 0.15%via GHSA
CVE-2026-55742Critical· 9.6Cotonti: Cross-Site Request Forgery in the administration rights handler
Cotonti: Cross-Site Request Forgery in the administration rights handler
▾ Midnightcotonti · cotonti/cotontiEPSS 0.15%via GHSA
CVE-2026-55745Medium· 5.4Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
▾ Sunlitcotonti · cotonti/cotontiEPSS 0.10%via GHSA
CVE-2026-55746High· 7.6Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
▾ Twilightcotonti · cotonti/cotontiEPSS 0.17%via GHSA