CVE-2026-90708
Yot CMS Cookie global.php login sql injection
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
| CWE | CWE-89 CWE-74 |
| Vendor | yot |
| Product | cms |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for yot cms
Be the first to know when new high vulnerabilities affecting yot cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Yot / CMS
3.3.0 3.3.1
References
vuldb.com: https://vuldb.com/vuln/403250 vuldb.com: https://vuldb.com/vuln/403250/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90708 vuldb.com: https://vuldb.com/submit/918272 github.com: https://github.com/dddwmr/CVE/blob/main/YOT%20III%20cookie%20auto-login%20SQL%20injection%20enables%20forged%20administrator%20sessions%20.md
Credits
๐ dwmm (VulDB User)