Vulnerability Intelligence Report
PbootCMS Password MemberController.php retrieve password recovery
CVE-2026-12066
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
No Active Exploit Signals
CVSS Base Score
6.9
MEDIUM
EPSS Probability:0.29%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-640 ↗Weak Password Recovery
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| n/a | PbootCMS | 3.2.0 (affected), 3.2.1 (affected), 3.2.2 (affected), 3.2.3 (affected), 3.2.4 (affected), 3.2.5 (affected), 3.2.6 (affected), 3.2.7 (affected), 3.2.8 (affected), 3.2.9 (affected), 3.2.10 (affected), 3.2.11 (affected), 3.2.12 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.288%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulDB · Researcher · Switzerland |
| Reserved | 2026-06-12T07:40:54 |
| Published | 2026-06-12T13:00:07 |
| Last Updated | 2026-06-12T13:34:40 |
Community Chatter & Buzz