CVE-2026-100521
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Summary
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the browser of any visitor who opens the link, including administrators.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cotonti | Cotonti | 0 <= 1.0.0 | affected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
- https://github.com/Cotonti/Cotonti/issues/1907
- https://github.com/Cotonti/Cotonti/pull/1908
- https://github.com/Cotonti/Cotonti/blob/1.0.0/plugins/search/search.header.php
- https://github.com/Cotonti/Cotonti/blob/1.0.0/plugins/search/search.page.first.php
- https://github.com/Cotonti/Cotonti
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-reflected-xss-via-search-highlight-parameter
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.