CVE-2026-71294 | Cotonti Comments CreateAction.php prepareComeBack ci/cb deserialization

SecurityVulns

A vulnerability marked as critical has been reported in Cotonti. Impacted is the function prepareComeBack of the file plugins/comments/controllers/actions/CreateAction.php of the component Comments. This manipulation of the argument ci/cb causes deserialization.

This vulnerability is registered as CVE-2026-71294. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More