CVE-2026-91939 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
- 🔗 github.com/Cotonti/Cotonti/issues/1888
- 🔗 github.com/Cotonti/Cotonti/pull/1889
- 🔗 github.com/Cotonti/Cotonti/blob/1.0.0/plugins/commen…
- 🔗 github.com/Cotonti/Cotonti/blob/1.0.0/plugins/commen…
- 🔗 github.com/Cotonti/Cotonti/blob/1.0.0/plugins/commen…
- 🔗 github.com/Cotonti/Cotonti
- 🔗 www.vulncheck.com/advisories/cotonti-1.0.0-comments-plugin-…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-22 | 2026-10-06 |
|---|---|---|
| ≥90 % | 491 | 353 |
| ≥50 % | 1475 | 1077 |
| ≥10 % | 0 | 2 |
| <10 % | 0 | 535 |
CVE-2026-91939 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can explo
Noch keine Analyse zu CVE-2026-91939
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.