{"id":"CVE-2021-47808","details":"Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.","modified":"2026-08-07T17:03:19.071939Z","published":"2026-01-16T00:16:25.707Z","references":[{"type":"WEB","url":"https://cotonti.com"},{"type":"WEB","url":"https://www.cotonti.com/download/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/cotonti-siena-maintitle-stored-cross-site-scripting"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/50016"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cotonti/cotonti","events":[{"introduced":"79bf592175f89fd8e537671169fe70fd3a34fe9c"},{"last_affected":"79bf592175f89fd8e537671169fe70fd3a34fe9c"}],"database_specific":{"cpe":"cpe:2.3:a:cotonti:cotonti_siena:0.9.19:-:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9.19-NA"},{"last_affected":"0.9.19-NA"}],"source":"CPE_STRING"}}],"versions":["0.9.19-NA","0.9.19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47808.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}