PHP Object Injection Vulnerability in Cotonti Comments Plugin
CVE-2026-91939
9.3CRITICAL
What is CVE-2026-91939?
The Cotonti Comments plugin version 1.0.0 contains a vulnerability that allows unauthenticated attackers to exploit PHP object injection by passing the ci GET parameter to the unserialize() function without an allowed_classes restriction. This flaw enables attackers to instantiate arbitrary PHP classes with controlled properties through crafted serialized payloads, which could lead to triggering gadget chains for database manipulation or arbitrary code execution. It is essential for users of the Cotonti platform to review their systems and apply necessary mitigations to prevent potential exploitation.
Affected Version(s)
Cotonti 1.0.0
