Vulnerabilities (CVE)

Filtered by vendor Beehiveforum Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-50910 1 Beehiveforum 1 Beehive Forum 2026-01-28 N/A 7.5 HIGH
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.