Skip to content
Noroxi

Cotonti records

6 published records for vendor cotonti.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 22
  2. 24
  3. 25
  4. 26

Bar: total · dark part: CISA KEV.

All records

6 records
  • CVE-2013-4789
    31Monitor

    SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via th

    HighCVSS 7.5Proof of conceptEPSS 3%

    cotonti · cotonti sienaAug 9, 2013

  • A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute

    MediumCVSS 5.4No exploitEPSS 0%

    cotonti · cotonti sienaFeb 8, 2024

  • A vulnerability has been found in Cotonti Siena v0.9.25.

    MediumCVSS 5.4No exploitEPSS 0%

    cotonti · cotonti sienaJun 2, 2025

  • Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting

    MediumCVSS 5.1No exploitEPSS 0%

    cotonti · cotonti sienaJan 15, 2026

  • Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.

    MediumCVSS 4.8No exploitEPSS 0%

    cotonti · cotonti sienaSep 5, 2022

  • Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).

    MediumCVSS 4.8No exploitEPSS 0%

    cotonti · cotonti sienaSep 5, 2022