CVE-2026-45701: Sulu
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6.
Affected products
- Sulu Sulu: before 2.6.23 (fixed in 2.6.23); from 3.0.0-alpha1, before 3.0.6 (fixed in 3.0.6)
Published 2026-06-01. Last modified 2026-07-22.