tag
Cwe-640
Critical
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
CVE-2025-58434·
FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints)
unpatched
Critical
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074)·
ARMember – Membership Plugin & Content Restriction (WordPress plugin)
patched