CVE WATCH / VULNERABILITY DETAIL
CVE-2026-108109
CRITICALCVSS 9.1NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or l
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-108107 CRITICAL 9.8
- CVE-2026-108108 HIGH 7.1
- CVE-2026-107806
- CVE-2026-108101 HIGH 7.5
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-104081 HIGH 8.1
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8