CVE detail
CVE-2025-54477
Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- https://developer.joomla.org/security-centre/1011-20250902-core-user-enumeration-in-passkey-authentication-method.htmldeveloper.joomla.org
No excerpt available.
Vendor Advisorydeveloper.joomla.orgSep 30, 2025, 4:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73630CVSS 6.9 · Medium
SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable…
- CVE-2026-72632CVSS 7.1 · High
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elasti…
- CVE-2026-58445CVSS 2.7 · Low
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- CVE-2026-59502CVSS 5.3 · Medium
CWE-203: Observable Discrepancy
- CVE-2026-73409CVSS 5.1 · Medium
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values dir…
- CVE-2025-13736CVSS 3.7 · Low
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canon…