Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to execute arbitrary JavaScript in victim browser sessions. | |
| Title | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter | |
| First Time appeared |
Cotonti
Cotonti cotonti Siena |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cotonti
Cotonti cotonti Siena |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T00:59:23.634Z
Reserved: 2026-09-26T00:48:21.175Z
Link: CVE-2026-100522
No data.
Status : Deferred
Published: 2026-09-26T01:17:00.700
Modified: 2026-09-26T01:17:00.823
Link: CVE-2026-100522
No data.
OpenCVE Enrichment
Updated: 2026-09-26T02:45:02Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')