← Back to browse · API

CVE-2025-63314

Severity
CRITICAL
CVSS
10.0
EPSS
0.00258
Risk score
40.09
CISA KEV
No
PoC
No
Published
2026-01-12
Modified
2026-07-05
First seen
2026-08-07
Aliases
EUVD-2026-1916, GHSA-9G5V-HMCJ-PXRC
Products
n/a:n/a n/a
Sources
euvd EUVD-2026-1916

Description

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

References