PoC Archive PoC Archive

tag

Password-Reset

Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912 network Unverified
CVE-2026-27912networkHIGH 8Unverified2026-08-11WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901 web Patched
CVE-2025-49901webCRITICAL 9.8Patched2026-07-06SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001) KEV RW EPSS 86%
CVE-2025-52691 web Patched
CVE-2025-52691webCRITICAL 10Patched2026-07-06Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CVE-2025-53580webCRITICAL 9.8Patched2026-07-06WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417 web Unverified
CVE-2026-12416, CVE-2026-12417webCRITICAL 9.8Unverified2026-07-05Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886 web Patched
CVE-2026-27886webCRITICALPatched2026-07-05SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
CVE-2026-0001 (tracked publicly as WT-2026-0001) web Patched
CVE-2026-0001webCRITICAL 9Patched2026-07-05SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760) KEV RW EPSS 96%
CVE-2026-23760 web Patched
CVE-2026-23760webCRITICAL 9.3Patched2026-07-05Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459 web Unverified
CVE-2026-7459webHIGH 7.5Unverified2026-07-05FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646) web Patched
CVE-2026-53647webMEDIUM 6.9Patched2026-07-05ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074) web Patched
CVE-2026-5076webCRITICAL 9.8Patched2026-07-05