MEDIUM 5.3 NVD
CVE-2026-101093
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verificat
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.
References
- https://github.com/Cotonti/Cotonti
- https://github.com/Cotonti/Cotonti/blob/1.0.0/system/admin/admin.users.php#L136-L140
- https://github.com/Cotonti/Cotonti/issues/1907#issuecomment-5845691148
- https://github.com/Cotonti/Cotonti/pull/1908
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-via-
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-28 via NVD.
vulnfeed aggregates 13624 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.