CVE-2026-93872
7.5 HIGHpublic exploit availablePublished 2026-09-18 · Updated 2026-09-22
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Public exploit & PoC references
All references
- https://github.com/Cotonti/Cotonti
- https://github.com/Cotonti/Cotonti/blob/1.0.0/plugins/comments/controllers/actions/EditAction.php
- https://github.com/Cotonti/Cotonti/blob/1.0.0/system/cache.php
- https://github.com/Cotonti/Cotonti/issues/1894
- https://github.com/Cotonti/Cotonti/pull/1897
- https://www.vulncheck.com/advisories/cotonti-1.0.0-php-object-injection-via-comments-plugin-edit-action-cb-parameter
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-59953PoC
- CRITICALCVE-2025-66455PoC
- HIGHCVE-2026-100308PoC
- HIGHCVE-2026-100841PoC
- HIGHCVE-2026-100843PoC
- HIGHCVE-2026-100845PoC
- HIGHCVE-2026-100846PoC
- UNSCOREDCVE-2026-101169
Related by shared AI tags and CWE weakness class. Browse the full archive.