PHP Object Injection Vulnerability in Cotonti Comments Plugin
CVE-2026-91939

9.3CRITICAL

Key Information:

Vendor

Cotonti

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91939?

The Cotonti Comments plugin version 1.0.0 contains a vulnerability that allows unauthenticated attackers to exploit PHP object injection by passing the ci GET parameter to the unserialize() function without an allowed_classes restriction. This flaw enables attackers to instantiate arbitrary PHP classes with controlled properties through crafted serialized payloads, which could lead to triggering gadget chains for database manipulation or arbitrary code execution. It is essential for users of the Cotonti platform to review their systems and apply necessary mitigations to prevent potential exploitation.

Affected Version(s)

Cotonti 1.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.