Unrated severityNVD Advisory· Published Jan 13, 2026· Updated Mar 5, 2026
Beehive Forum - Account Takeover
CVE-2022-50910
Description
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.
Affected products
2- Range: = 1.5.2
- Beehive Forum/Beehive Forumv5Range: 1.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- imgur.com/a/hVlgpCgmitreexploit
- www.exploit-db.com/exploits/50923mitreexploit
- www.vulncheck.com/advisories/beehive-forum-account-takeovermitrethird-party-advisory
- sourceforge.net/projects/beehiveforum/mitreproduct
- www.beehiveforum.co.ukmitreproduct
News mentions
0No linked articles in our index yet.