OurCVEs
Register
Back to feed
Critical
GHSA-g7vj-c29h-3h5m
(CVE-2026-92161)

Published Sep 25, 2026

CVSS

9.8

CRITICAL

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.
—

Affected packages

0
Summary

FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider

Developer impact

Recommended action

Affected packages
Sources