
CVE-2026-26744 A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application retu… https://www.cve.org/CVERecord?id=CVE-2026-26744
Post summary
The CVE record announces a user enumeration flaw in FormaLMS's password recovery endpoint, but provides no PoC, exploit, or patch details.

