Predictable Password Reset Token Vulnerability in NivoCart by NivoCart
CVE-2026-94107

9.2CRITICAL

Key Information:

Vendor

Nivocart

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-94107?

NivoCart, up to version 2.4.0, has a vulnerability within its forgotten.php endpoint, where password reset tokens are generated using a predictable method. This allows attackers who have access to an administrator's email address to exploit this weakness by requesting a password reset. The generated recovery codes do not include any rate limiting or expiration mechanisms, permitting unauthorized access to administrative accounts through predictable token values. For detailed insights, refer to the product's issue tracking and more technical specifications in its reset token generation and user retrieval methods. This vulnerability poses significant security risks, and users are urged to implement necessary protective measures.

Affected Version(s)

nivocart 0 <= 2.4.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.