Tag
Flarum versions prior to 1.8.16 are vulnerable to an unauthenticated password reset token expiry bypass, allowing attackers to reuse expired tokens to gain unauthorized account access.