CVE-2026-91939

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 21:16

Updated : 2026-09-15 21:16


NVD link : CVE-2026-91939

Mitre link : CVE-2026-91939

CVE.ORG link : CVE-2026-91939


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data