AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-25961

HIGH · CVSS 8 EPSS 0.95% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2021-25961
Severity
HIGH
CVSS
8
EPSS
0.95%

Original NVD Description

In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.