PHP Object Injection in Cotonti 1.0.0 Comments Plugin by Cotonti
CVE-2026-93872

7.7HIGH

Key Information:

Vendor

Cotonti

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93872?

The comments plugin in Cotonti 1.0.0 contains a vulnerability where the base64-decoded cb parameter is passed to unserialize() without restrictions on allowed_classes. This flaw allows registered users with comment writing privileges to potentially instantiate any PHP objects, leading to risks such as file manipulation or remote code execution via crafted gadget chains.

Affected Version(s)

Cotonti 1.0.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.