CVE-2025-44115: Cotonti Siena

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.

Affected products

  • Cotonti Cotonti Siena: version 0.9.25 only

Published 2025-06-02. Last modified 2026-06-17.