CVE-2026-90708: Yot CMS Cookie global.php login sql injection
A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3user/yot3pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered exposed?
Yot CMS deployments running version 3.3.1 or earlier should be considered affected. The vulnerable login handling is in global.php's Cookie Handler component.
Does an attacker need an account or user interaction to exploit this issue?
No. The supplied vector indicates remote exploitation with low attack complexity, no privileges, and no user interaction required. The attacker manipulates the yot3_user and yot3_pass arguments.
How urgent is remediation?
Remediation should be prioritized because a public exploit is available and the issue can be attacked remotely without authentication. The reported impact includes partial compromise of confidentiality, integrity, and availability.