high · CVSS v3 7.5 · CVSS v4 7.7
CVE-2026-93872
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comment…
Description
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.
Scores
- Severity
- high
- CVSS v2
- 7.1
- CVSS v3
- 7.5
- CVSS v4
- 7.7
- EPSS
- —