Description
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
Remediation
References
Related Vulnerabilities
WordPress Plugin MainWP Child Reports SQL Injection (2.0.7)
Moodle Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-26047)
WordPress Plugin WP Accurate Form Data Multiple Vulnerabilities (1.2)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (4.10.7)