CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100521

MEDIUMCVSS 6.1NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the browser of any visitor who

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100521 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100521

MEDIUMCVSS 6.1NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the browser of any visitor who

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]