Description
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The Cotonti 1.0.0 Comments plugin accepts a GET parameter named ci and forwards its value directly to PHP's unserialize() function without restricting allowed_classes. This flaw enables an unauthenticated attacker to supply a crafted serialized payload that instantiates arbitrary PHP objects. Through gadget chains embedded in the payload, an attacker can manipulate the database or execute arbitrary code on the host. The vulnerability is classified as CWE-502, which indicates insecure deserialization.

Affected Systems

The flaw is present in the Cotonti Comments plugin. The vendor field names the product as Cotonti, and the CPE string cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* indicates the package, but no specific version is listed in the CNA data apart from the title mentioning 1.0.0. No other versions have been confirmed to contain this defect in the provided data.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, signifying critical impact when exploited. The EPSS score of less than 1% indicates a very low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint without authentication, send a crafted ci parameter in a GET request, and potentially trigger gadget chain execution for code execution or database compromise. The overall risk remains high because of the severity, but the current likelihood of exploitation is low.

Generated by OpenCVE AI on September 18, 2026 at 14:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor update that validates or restricts the ci parameter during unserialization when calling unserialize().
  • If an update is not available, modify the plugin code to supply an explicit allowed_classes array to unserialize() or replace unserialize() with a safer parsing method such as json_decode() for that parameter.
  • Configure a web application firewall or input validation layer to reject any ci parameter that contains a serialized string pattern, thereby blocking potential gadget chain payloads.

Generated by OpenCVE AI on September 18, 2026 at 14:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Cotonti cotonti
Cotonti siena
Vendors & Products Cotonti cotonti
Cotonti siena

Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
Title Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter
First Time appeared Cotonti
Cotonti cotonti Siena
Weaknesses CWE-502
CPEs cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:*
Vendors & Products Cotonti
Cotonti cotonti Siena
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cotonti Cotonti Cotonti Siena Siena
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:31.728Z

Reserved: 2026-09-15T11:07:01.912Z

Link: CVE-2026-91939

cve-icon Vulnrichment

Updated: 2026-09-16T19:17:45.626Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T21:16:48.957

Modified: 2026-09-16T20:21:01.047

Link: CVE-2026-91939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:45:09Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data