Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91939

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

EPSS

Процентиль: 47%
0.00594
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
debian
3 дня назад

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ...

CVSS3: 9.8
github
3 дня назад

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

EPSS

Процентиль: 47%
0.00594
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502