CVE-2026-93872

Source
https://cve.org/CVERecord?id=CVE-2026-93872
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93872.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93872
Published
2026-09-18T19:56:37Z
Modified
2026-09-19T11:45:42Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter
Details

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-502"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93872.json"
}
References

Affected packages

Git / github.com/cotonti/cotonti

Affected ranges

Type
GIT
Repo
https://github.com/cotonti/cotonti
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93872.json"