{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acotonticotonti1.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cotonti:cotonti:1.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-91939"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Comments plugin (1.0.0)"],"_cs_severities":["critical"],"_cs_tags":["php-object-injection","rce","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Cotonti"],"content_html":"\u003cp\u003eThe Cotonti 1.0.0 Comments plugin contains a critical security vulnerability (CVE-2026-91939) involving improper input validation. The plugin accepts a 'ci' GET parameter from unauthenticated users and passes this value directly to the PHP 'unserialize()' function without applying an 'allowed_classes' restriction. This allows remote attackers to perform PHP object injection, enabling the instantiation of arbitrary classes within the application context. By providing a crafted serialized payload, an attacker can manipulate object properties to trigger gadget chains. Depending on the available classes within the environment, this vulnerability can be leveraged to achieve arbitrary code execution or unauthorized database manipulation, posing a significant risk to the integrity and confidentiality of the host system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-91939 allows for unauthenticated remote code execution. This can lead to full system compromise, unauthorized access to the underlying database, and potential data exfiltration or service disruption. All instances of Cotonti running version 1.0.0 with the affected Comments plugin enabled are at risk of complete compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all internet-facing Cotonti instances within the environment. Until a vendor patch is applied, restrict access to the web application at the network perimeter or implement WAF rules to inspect and block 'ci' GET parameters containing serialized PHP objects, identifiable by strings such as 'O:7:' or 's:x:'. Verify the current version of the Comments plugin and evaluate the necessity of disabling the plugin if an immediate upgrade to a patched version is not possible.\u003c/p\u003e\n","date_modified":"2026-09-15T21:53:03Z","date_published":"2026-09-15T21:53:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cotonti-cve-2026-91939/","summary":"Cotonti 1.0.0 is vulnerable to unauthenticated remote code execution via a PHP object injection flaw in the Comments plugin's 'ci' GET parameter.","title":"Unauthenticated PHP Object Injection in Cotonti Comments Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cotonti-cve-2026-91939/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cotonti:cotonti:1.0.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}