Open Redirect Vulnerability in Cotonti by Cotonti Team
CVE-2026-93869

5.3MEDIUM

Key Information:

Vendor

Cotonti

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93869?

Cotonti, versions up to 1.0.0, possesses an open redirect vulnerability in the cot_url_check() function. This issue stems from an insufficient validation process of redirect destinations due to a regular expression that lacks an end-of-string anchor. Exploiting this vulnerability, attackers can construct malicious URLs starting with the site domain, enabling unauthorized redirection of users to their own hostile web pages via the ratings plugin or other redirect mechanisms. Proper sanitization and validation measures are crucial to mitigate this security risk.

Affected Version(s)

Cotonti 0 <= 1.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.