Loading market data...
← Back to CVE feed

CVE-2026-93872

HIGH CVSS 7.5 View on NVD ↗

Description

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Sep 18, 2026 20:17 UTC Modified: Sep 18, 2026 20:17 UTC