Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Lorenzo Bruno

#50474de 56,331
5.3CVSS total
Vulnerabilidades · 1
PT-2026-20941
5.3
2026-02-19
Forma Lms · Forma Lms · CVE-2026-26744
**Name of the Vulnerable Software and Affected Versions** FormaLMS versions 4.1.18 and below **Description** A flaw exists in the password recovery functionality of FormaLMS that allows for user enumeration. An unauthenticated attacker can determine valid registered usernames by observing differing error messages returned by the application. This is accessible via the `/lostpwd` API endpoint. The application reveals whether a username exists based on the response received. **Recommendations** Versions prior to 4.1.18 should be updated.