<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 15:21:55 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-12981 — CAFEHAUS API &lt;= 1.0.0 - Unauthenticated Arbitrary User Password Reset</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-12981</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown CAFEHAUS API&lt;/p&gt;
&lt;p&gt;The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown CAFEHAUS API&lt;/p&gt;
&lt;p&gt;The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-12981</guid>
    </item>
  </channel>
</rss>
