CVE-2019-16669: Pagekit

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.

Affected products

  • Pagekit Pagekit: version 1.0.17 only

Published 2019-09-21. Last modified 2026-06-17.