Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attributed to authenticated victims to the administrator inbox. | |
| Title | Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin | |
| First Time appeared |
Cotonti
Cotonti cotonti Siena |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cotonti
Cotonti cotonti Siena |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T20:21:09.601Z
Reserved: 2026-09-18T19:39:42.366Z
Link: CVE-2026-93873
Updated: 2026-09-18T20:21:03.207Z
Status : Received
Published: 2026-09-18T20:17:35.400
Modified: 2026-09-18T21:18:49.167
Link: CVE-2026-93873
No data.
OpenCVE Enrichment
No data.
