PHP Object Injection in Cotonti 1.0.0 Comments Plugin by Cotonti
CVE-2026-93872
7.7HIGH
What is CVE-2026-93872?
The comments plugin in Cotonti 1.0.0 contains a vulnerability where the base64-decoded cb parameter is passed to unserialize() without restrictions on allowed_classes. This flaw allows registered users with comment writing privileges to potentially instantiate any PHP objects, leading to risks such as file manipulation or remote code execution via crafted gadget chains.
Affected Version(s)
Cotonti 1.0.0
