
CVE-2026-30841 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["email"] directly in… https://www.cve.org/CVERecord?id=CVE-2026-30841
Post summary
The post highlights that Wallos's passwordreset.php exposed GET parameters prior to version 4.6.2, offering technical details of CVE‑2026‑30841 without mentioning exploits, patches, or PoC.


