CVETodo[verified]@CveTodoDisclosure
The tweet discloses a critical flaw in EverShop’s forgot‑password flow that leaks reset tokens via API responses.
CVEFind.com@CveFindComPatch
The tweet announces a critical CVE (CVE‑2026‑28213) that enables account takeover via EverShop’s Forgot Password feature and urges users to update to the patched version 2.1.1.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-28213, a critical vulnerability in EverShop’s Forgot Password feature affecting versions before 2.1.1, with a CVSS score of 9.8.
PulsePatch.io@pulsepatchioPatch
EverShop suffers an account‑takeover flaw from exposed reset tokens, and a specific patch commit along with a remedy link are provided.
CVE@CVEnewGeneral
The post notes a CVE affecting EverShop's Forgot Password feature but offers no further technical or operational detail.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text lists CVE‑2026‑28213 and notes it is an authentication bypass in EverShop’s password reset feature, linking to a details page but providing no further technical or operational context.