Known Vulnerabilities for Forgot Password by Mendix
Listed below are 5 of the newest known vulnerabilities associated with "Forgot Password" by "Mendix".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64829 json | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained ... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-61451 json | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field i... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-56267 json | Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint tha... | Not Provided | 2026-06-20 | 2026-06-22 |
| CVE-2026-53928 json | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-for... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-44987 json | SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions c... | Not Provided | 2026-05-08 | 2026-05-12 |
| CVE-2026-44679 json | Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated at... | Not Provided | 2026-05-14 | 2026-05-14 |
| CVE-2026-44306 json | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-42606 json | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware un... | Not Provided | 2026-05-09 | 2026-05-12 |
| CVE-2026-31283 json | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. whic... | Not Provided | 2026-04-13 | 2026-04-24 |
| CVE-2026-30459 json | An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the pass... | Not Provided | 2026-04-16 | 2026-07-05 |