htmlspecialchars of the file passwordreset.php. Performing a manipulation of the argument token/email results in cross site scripting.This vulnerability is reported as CVE-2026-30841. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.