VulnSea

Cotonti has 11 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 4 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-352 (5). Most affected products: Cotonti (7), cotonti/cotonti (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
7 prev 4

Products

  • Cotonti 7
  • cotonti/cotonti 4
11
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Cotonti vulnerabilities

CVEs affecting Cotonti, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-93873Medium· 4.3PoC
3d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attri…

TwilightCotonti · CotontiEPSS 0.16%via NVD
CVE-2026-93872High· 7.5
3d ago

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potent…

TwilightCotonti · CotontiEPSS 0.44%via NVD
CVE-2026-93871Medium· 5.4PoC
3d ago

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pa…

TwilightCotonti · CotontiEPSS 0.17%via NVD
CVE-2026-93870Medium· 4.3
3d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modi…

SunlitCotonti · CotontiEPSS 0.14%via NVD
CVE-2026-93869Medium· 6.1PoC
3d ago

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by sup…

TwilightCotonti · CotontiEPSS 0.22%via NVD
CVE-2026-93868High· 8.1PoC
3d ago

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the s…

MidnightCotonti · CotontiEPSS 0.61%via NVD
CVE-2026-91939Critical· 9.8PoC
6d ago

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can ex…

AbyssalCotonti · CotontiEPSS 0.59%via NVD
CVE-2026-55744High· 8.1
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Twilightcotonti · cotonti/cotontiEPSS 0.15%via GHSA
CVE-2026-55742Critical· 9.6
3mo ago

Cotonti: Cross-Site Request Forgery in the administration rights handler

Cotonti: Cross-Site Request Forgery in the administration rights handler

Midnightcotonti · cotonti/cotontiEPSS 0.15%via GHSA
CVE-2026-55745Medium· 5.4
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Sunlitcotonti · cotonti/cotontiEPSS 0.10%via GHSA
CVE-2026-55746High· 7.6
3mo ago

Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module

Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module

Twilightcotonti · cotonti/cotontiEPSS 0.17%via GHSA
Cotonti vulnerabilities (CVEs) · VulnSea