Total vulnerabilities in the database
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: