CVE-2026-58144: Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter
Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbitrary script payloads by supplying malicious HTML in the ntitle parameter processed through the TXT filter in pfs.main.php. Attackers can create a folder with a crafted title containing script tags that are stored unescaped in the database and execute in the browser of any user who views the folder listing, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58144?
The severity of CVE-2026-58144 is medium with a CVSS score of 5.4.
How do I fix CVE-2026-58144?
To fix CVE-2026-58144, update to the latest version of Cotonti Siena that does not contain the vulnerability.
What type of vulnerability is CVE-2026-58144?
CVE-2026-58144 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-58144?
Authenticated users with PFS access in Cotonti Siena 0.9.26 and earlier are affected by CVE-2026-58144.
What can attackers do with CVE-2026-58144?
Attackers can inject arbitrary script payloads through the ntitle parameter, potentially leading to malicious actions or data theft.