Cotonti
Cotonti: vulnerabilidades y CVE
Cotonti tiene 16 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses16
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-101093 | Media (5.3) | 0.12% | — | 28 sept 2026 | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that… |
| CVE-2026-100524 | Media (5.3) | 0.12% | — | 25 sept 2026 | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links… |
| CVE-2026-100523 | Media (5.1) | 0.19% | — | 25 sept 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded… |
| CVE-2026-100522 | Media (5.1) | 0.21% | — | 25 sept 2026 | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft… |
| CVE-2026-100521 | Media (5.1) | 0.20% | — | 25 sept 2026 | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected… |
| CVE-2026-93873 | Media (5.3) | 0.19% | — | 18 sept 2026 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send… |
| CVE-2026-93872 | Alta (7.7) | 0.71% | — | 18 sept 2026 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP… |
| CVE-2026-93871 | Media (5.1) | 0.27% | — | 18 sept 2026 | Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts.… |
| CVE-2026-93870 | Media (5.3) | 0.19% | — | 18 sept 2026 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit… |
| CVE-2026-93869 | Media (5.3) | 0.36% | — | 18 sept 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the… |
| CVE-2026-93868 | Crítica (9.2) | 0.73% | — | 18 sept 2026 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated… |
| CVE-2026-55746 | Alta (7) | 0.30% | — | 18 jun 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip… |
| CVE-2026-55745 | Media (5.3) | 0.14% | — | 18 jun 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates… |
| CVE-2026-55744 | Alta (8.6) | 0.20% | — | 18 jun 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes… |
| CVE-2026-55742 | Crítica (9.4) | 0.21% | — | 18 jun 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group… |
| CVE-2026-55741 | Alta (8.7) | 0.21% | — | 18 jun 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update')… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.