Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108109

CRITICAL NVD
CVSS Score 9.1
Severity CRITICAL
Published Oct 09, 2026
Vendor unknown

Description

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.

References