Cotonti is a modestly represented open-source content-management and portal platform whose vulnerability profile centers on its Siena product line, with the durable signal concentrated in application-layer input-handling flaws such as cross-site scripting and SQL injection. Its disclosures frequently acquire public exploit code, making timely patching essential for web-facing deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cotonti over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4789HIGH SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php. | Aug 9, 2013 | 7.5 | 29 | NO | YES |
CVE-2021-47808MEDIUM Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code th | Jan 16, 2026 | 5.4 | 23 | NO | NO |
CVE-2022-39840MEDIUM Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM). | Sep 5, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-39839MEDIUM Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post. | Sep 5, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-24115MEDIUM A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a cra | Feb 8, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-44115MEDIUM A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of titl | Jun 2, 2025 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cotonti.
Media articles that mention a CVE ID that affects a product developed by Cotonti — matched by CVE ID, not by vendor name.