CVE-2026-100521

CVE-2026-100521 published: Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that...

View full NVD advisory → ← Back to CVE watch