PT-2026-50646 · Cotonti · Cotonti

CVE-2026-55746

·

Published

2026-06-18

·

Updated

2026-08-10

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cotonti version 1.0.0
Description The Personal File Storage (PFS) module allows authenticated users to store HTML or JavaScript within a folder title. This occurs because the pff title variable is imported using a 'TXT' filter that fails to strip or encode HTML. In the file modules/pfs/inc/pfs.main.php, the title is assigned to the PFF ROW TITLE template variable without using htmlspecialchars(), and the file modules/pfs/tpl/pfs.tpl outputs {PFF ROW TITLE} unescaped. Consequently, the injected script executes in the browser of any user viewing the folder listing, including users accessing public folders. This is a stored Cross-Site Scripting (XSS) issue, where malicious scripts are permanently stored on the server and served to other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55746
GHSA-86HP-HF3J-3M8R

Affected Products

Cotonti