CRITICAL 9.8 CVE-2026-91939 Published 15 Sept 2026

Cotonti Comments Plugin PHP Object Injection

Worried this affects one of your servers?

Cotonti 1.0.0 Comments plugin is vulnerable to PHP object injection.

Cotonti plugin fails to restrict classes when unserializing the 'ci' GET parameter, allowing unauthenticated attackers to execute arbitrary PHP code.

Exploiting this vulnerability can lead to database manipulation or code execution.

Reference: CVE-2026-91939 on NVD

← Back to Security News