CVE-2026-93873
EUVD-2026-8337018.09.2026, 20:17
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attributed to authenticated victims to the administrator inbox.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References