CVE-2026-29199
Published May 4, 2026phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted…
- evidence mentions
- 1
- Buzz score
- 11.9