Junglewise Threat Intelligence

CVE-2026-55746: Cotonti stored XSS in Personal File Storage module

CVE-2026-55746 · Severity: high · CVSS 7.6 · Published 2026-06-18

Technologies: cotonti/cotonti (Packagist), Cotonti. Vendors: Packagist, Cotonti.

Executive brief

Cotonti, a content management system, contains a security flaw in its Personal File Storage (PFS) module. An authenticated user can create a folder with a malicious title containing hidden scripts. When other users or administrators view these folder listings, the script executes in their browser, potentially allowing the attacker to steal session information or perform unauthorized actions on their behalf.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Cotonti 1.0.0 (specifically commit f43f1fc3) within the Personal File Storage (PFS) module. The root cause is the improper neutralization of the 'pff_title' input; the 'TXT' filter used during import fails to strip or encode HTML tags because the tag check in 'cot_import' is disabled. Furthermore, 'modules/pfs/inc/pfs.main.php' assigns this title to the 'PFF_ROW_TITLE' template variable without calling 'htmlspecialchars()', and the corresponding template 'modules/pfs/tpl/pfs.tpl' outputs the variable unescaped. An authenticated attacker can exploit this by creating a folder with a malicious JavaScript payload in the title, which executes when any user views the folder listing.

Affected products

  • Cotonti Cotonti 1.0.0 (commit f43f1fc3)

Timeline

  • 2026-06-18: advisory: NVD publication date

References

Related threats