Cross-Site Request Forgery in Cotonti Ratings Plugin
CVE-2026-93870
5.3MEDIUM
What is CVE-2026-93870?
The version 1.0.0 of Cotonti includes a vulnerability in its ratings plugin where anti-CSRF token validation is lacking. This flaw permits attackers to craft malicious pages that can trigger POST requests to alter stored ratings when accessed by logged-in users, effectively enabling the unauthorized modification of user-generated ratings.
Affected Version(s)
Cotonti 0 <= 1.0.0
