CVE-2026-58144Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbitrary script payloads by supplying malicious HTML in the ntitle parameter processed through the TXT filter in pfs.main.php. Attackers can create a folder with a crafted title containing script tags that are stored unescaped in the database and execute in the browser of any user who views the folder listing, including administrators.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Technical Details · 2026-07-10: 207-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58144 Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbitrary script paylo… https://www.cve.org/CVERecord?id=CVE-2026-58144 ----- Traducción: CVE-2026-58144 Cot… http://infoflow.cloud`

    Post summary

    The message announces a stored XSS flaw in Cotonti Siena 0.9.26 and earlier, giving the CVE ID, technical details, and links to the CVE record, but provides no PoC, exploit code, or mitigation advice.

    0000043
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58144 Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbitrary script paylo… https://www.cve.org/CVERecord?id=CVE-2026-58144

    Post summary

    The post announces a stored XSS flaw in Cotonti Siena 0.9.26 and earlier that can be exploited by authenticated users with PFS access, but it provides no evidence of exploitation, a PoC, or a patch.

    00000630
    57.8K followersView on X

Explore more