References https://github.com/projectdiscovery/nuclei-templates/commits?after=6f5cf7ee077d5faedebcdf8f15cc63f18900a21c+34 https://github.com/projectdiscovery/nuclei-templates/commit/e445aa0 https://stack.chaitin.com/vuldb/detail/51144564-e928-4e12-b4f7-12820e67315e https://developer.aliyun.com/article/131721 https://vuls.vercel.app/Vulnerability-Wiki/edge/EDGE/TG8-%E9%98%B2%E7%81%AB%E5%A2%99%E4%B8%AD%E7%9A%84-RCE-%E5%92%8C%E5%AF%86%E7%A0%81%E6%B3%84%E6%BC%8F/ https://cloud.tencent.com/developer/article/1771200 https://www.cnblogs.com/zktq/p/14925846.html https://github.com/Al1ex/CheckPWD
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞PoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication BypassPoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2026-20079: Cisco Secure Firewall Management Center - Authentication BypassPoCCVE-2025-62512: Piwigo - User Enumeration via Password ResetBMC FootPrints /footprints/servicedesk/passwordreset/request/ 权限绕过漏洞(CVE-2025-71257/CVE-2025-71258/CVE-2025-71259/CVE-2025-71260)PoCCVE-2025-27506: NocoDB < 0.258.0 - Reflected XSS in Password ResetPoCCVE-2022-3236: Sophos Firewall <= 19.0 MR1 - Remote Code ExecutionPoCCVE-2025-56132: LiquidFiles < 4.2 - User Enumeration via Password ResetPoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password Reset