CVE-2026-93873
4.3 MEDIUMpublic exploit availablePublished 2026-09-18 · Updated 2026-09-22
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attributed to authenticated victims to the administrator inbox.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weaknesses
CWE-352
Public exploit & PoC references
All references
- https://github.com/Cotonti/Cotonti
- https://github.com/Cotonti/Cotonti/blob/1.0.0/plugins/contact/contact.php
- https://github.com/Cotonti/Cotonti/issues/1895
- https://github.com/Cotonti/Cotonti/pull/1903
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-in-the-contact-plugin
- https://github.com/Cotonti/Cotonti/issues/1895
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-15399
- MEDIUMCVE-2026-100524PoC
- MEDIUMCVE-2026-100712PoC
- UNSCOREDCVE-2026-100747
- UNSCOREDCVE-2026-100748
- UNSCOREDCVE-2026-100749
- MEDIUMCVE-2026-100873PoC
- MEDIUMCVE-2026-101093PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.