CVE-2026-100524 MEDIUM

CVE-2026-100524: Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager

Vendor Cotonti
Product Cotonti
Weakness CWE-352 · CSRF
Published September 26, 2026
Last update September 26, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links or embed images to force administrators to install, update, pause, or unpause extensions by tricking them into visiting a malicious page while authenticated.

Key dates

02Disclosure timeline

September 26, 2026 CVE published

Related vulnerabilities

04Related CVE