{"id":"CVE-2026-93872","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-93872","summary":"Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions…","details":"Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.","published":"2026-09-18T20:17:35.250","modified":"2026-09-18T20:17:35.250","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/Cotonti/Cotonti/pull/1897","label":"Cotonti/Cotonti#1897"},"references":[{"type":"WEB","url":"https://github.com/Cotonti/Cotonti"},{"type":"WEB","url":"https://github.com/Cotonti/Cotonti/blob/1.0.0/plugins/comments/controllers/actions/EditAction.php"},{"type":"WEB","url":"https://github.com/Cotonti/Cotonti/blob/1.0.0/system/cache.php"},{"type":"WEB","url":"https://github.com/Cotonti/Cotonti/issues/1894"},{"type":"WEB","url":"https://github.com/Cotonti/Cotonti/pull/1897"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/cotonti-1.0.0-php-object-injection-via-comments-plugin-edit-action-cb-parameter"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T20:17:35.250"}}