HIGHVulnerability
CVE-2026-71294
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to comments (the default setting in plugins/comments/comments.setup.php).
Properties
- severity
- HIGH
- score
- 7.6
- cve_id
- CVE-2026-71294
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- published_at
- 2026-08-05T13:24:54.180
- last_modified
- 2026-08-26T17:13:24.800
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Deserialization of Untrusted Data
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph