PoC Archive PoC Archive

tag

Cwe-640

Critical
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
CVE-2025-58434· FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints) unpatched
Critical
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074)· ARMember – Membership Plugin & Content Restriction (WordPress plugin) patched