Threat intelligence dashboard
CVE-2026-100522medium

Cotonti through 1.0.0 Reflected XSS via message.php lng parameter

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to execute arbitrary JavaScript in victim browser sessions.

Risk score

5.1

CVSS 4.0

Vendor
Cotonti
Product
Cotonti
CWE
CWE-79
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Cotonti

Cotonti

Version / rangeStatusType
0 to 1.0.0affectedcustom

Technical metrics

5.1

CVSS 4.0

Severity
medium
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

6.1

CVSS 3.1

Severity
medium
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N