Junglewise Threat Intelligence

CVE-2026-100521: Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML

CVE-2026-100521 · Severity: medium · CVSS 6.1 · Published 2026-09-26