CVE-2026-71294
EUVD-2026-5337905.08.2026, 13:24
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to comments (the default setting in plugins/comments/comments.setup.php).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration