← Back to CVE List
CVE-2026-93873NVD
Vulnerability Summary
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attributed to authenticated victims to the administrator inbox.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
External References
- https://github.com/Cotonti/Cotonti/issues/1895
- https://github.com/Cotonti/Cotonti/pull/1903
- https://github.com/Cotonti/Cotonti/blob/1.0.0/plugins/contact/contact.php
- https://github.com/Cotonti/Cotonti
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-in-the-contact-plugin