CVE-2026-100521: Cotonti through 1.0.0 Reflected XSS via search highlight parameter
Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the highlight parameter that executes in the browser of any visitor who opens the link, including administrators.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and what interaction is required?
An unauthenticated attacker can craft a malicious link containing JavaScript in the search highlight parameter. The script executes when a visitor opens that link, so exploitation requires user interaction.
Are administrators at risk?
Yes. The injected script can execute in the browser of any visitor who opens the crafted link, including an administrator.
Which deployments are affected?
Cotonti versions through 1.0.0 are affected when the search plugin processes the highlight parameter without HTML or JavaScript escaping.
How can I identify attempted exploitation?
Review search requests and related logs for highlight parameter values containing HTML, JavaScript, or other injected markup. Affected requests rely on a victim opening an attacker-controlled search link.