« Volver al listado

Cotonti

Cotonti: vulnerabilidades y CVE

Cotonti tiene 16 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses16
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-101093Media (5.3)0.12%—28 sept 2026
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that…
CVE-2026-100524Media (5.3)0.12%—25 sept 2026
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links…
CVE-2026-100523Media (5.1)0.19%—25 sept 2026
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded…
CVE-2026-100522Media (5.1)0.21%—25 sept 2026
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft…
CVE-2026-100521Media (5.1)0.20%—25 sept 2026
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected…
CVE-2026-93873Media (5.3)0.19%—18 sept 2026
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send…
CVE-2026-93872Alta (7.7)0.71%—18 sept 2026
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP…
CVE-2026-93871Media (5.1)0.27%—18 sept 2026
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts.…
CVE-2026-93870Media (5.3)0.19%—18 sept 2026
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit…
CVE-2026-93869Media (5.3)0.36%—18 sept 2026
Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the…
CVE-2026-93868Crítica (9.2)0.73%—18 sept 2026
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated…
CVE-2026-55746Alta (7)0.30%—18 jun 2026
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip…
CVE-2026-55745Media (5.3)0.14%—18 jun 2026
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates…
CVE-2026-55744Alta (8.6)0.20%—18 jun 2026
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes…
CVE-2026-55742Crítica (9.4)0.21%—18 jun 2026
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group…
CVE-2026-55741Alta (8.7)0.21%—18 jun 2026
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update')…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution7
  2. T1059.007 JavaScript3
  3. T1189 Drive-by Compromise2
  4. T1566.002 Spearphishing Link2
  5. T1078.001 Default Accounts1
  6. T1187 Forced Authentication1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Cotonti