CVE-2012-5618: Ushahidi

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

Affected products

  • Ushahidi Ushahidi: before 2.6.1 (fixed in 2.6.1)

Published 2020-02-04. Last modified 2026-06-16.