Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains. | |
| Title | Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter | |
| First Time appeared |
Cotonti
Cotonti cotonti Siena |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cotonti
Cotonti cotonti Siena |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T19:56:37.540Z
Reserved: 2026-09-18T19:39:42.007Z
Link: CVE-2026-93872
No data.
Status : Received
Published: 2026-09-18T20:17:35.250
Modified: 2026-09-18T20:17:35.250
Link: CVE-2026-93872
No data.
OpenCVE Enrichment
No data.
-
CWE-502
Deserialization of Untrusted Data