PACKAGIST · SEPTEMBER 2026 · EARLY WARNING

Cotonti Comments Plugin Vulnerability: Critical Risk Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
cotonti comments plugin (packagist)
Patched version
Not yet available
CVE-2026-91939

An early warning has been issued for a critical vulnerability in the Cotonti Comments plugin version 1.0.0. This vulnerability allows unauthenticated attackers to instantiate arbitrary PHP classes, potentially leading to database manipulation or code execution.

What happened

The Cotonti Comments plugin version 1.0.0 reportedly passes the ci GET parameter to unserialize() without the allowed_classes restriction. This design flaw allows unauthenticated attackers to inject arbitrary PHP objects, which can be exploited to trigger gadget chains. Attackers may achieve database manipulation or execute arbitrary code on the affected system.

This vulnerability is under investigation and has not been exploited in the wild as of the latest reports. However, the potential impact is severe, with a CVSS score of 9.8, indicating a critical severity level.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cotonti comments plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if you are using the Cotonti Comments plugin version 1.0.0.

What should I do right now?

Assess your systems for the Cotonti Comments plugin version 1.0.0 and either upgrade to a patched version or remove the plugin if no fix is available.

Is there an official fix available?

No official fix has been published yet. Monitor the primary sources for updates.

How severe is this vulnerability?

The vulnerability is rated as critical with a CVSS score of 9.8.

Sources

Join the 0Day waitlist →

← Back to all threats