CWE-324
CVEs classified under CWE-324, newest first.
3 CVEsRSS
CVE-2026-39923High· 8.1Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint
Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordC…
▾ TwilightEPSS 0.26%via NVD
CVE-2026-54787Low· 3.1sigstore-go is a Go library for Sigstore signing and verification
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without…
▾ Sunlitsigstore · github.com/sigstore/sigstore-goEPSS 0.09%via NVD
CVE-2026-52809Medium· 6.8Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
▾ Sunlitgogs · gogs.io/gogsEPSS 0.20%via GHSA