The Change Password For Frontend Users Project maintains a narrowly scoped utility focused on password-reset functionality for web applications, with a limited but defined attack surface centered on session-management logic. The durable signal observed is insufficient session expiration, a weakness class that can allow unauthorized access if password-reset tokens or sessions persist beyond their intended lifetime. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Change Password For Frontend Users Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47406CRITICAL An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existin | Dec 14, 2022 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Change Password For Frontend Users Project.
Media articles that mention a CVE ID that affects a product developed by Change Password For Frontend Users Project — matched by CVE ID, not by vendor name.