All verified exploits

CVE-2026-33707 Predictable Password Reset Token

Deterministic critical Chamilo Added cve-verified-cve-2026-33707

Detects Chamilo LMS instances before 1.11.38 where the password reset mechanism generates tokens using sha1(email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication, leading to full account takeover. Update to Chamilo 1.11.38 or 2.0.0-RC.3.

Is your app exploitable through CVE-2026-33707?

Scan your domain free