CVE-2025-54321: Reset Password Email Bombing Description The reset password function does not implement rate limiting for the target email address. This allows for an Email Bombing attack. CVSS Score 7.1 (High) Attack Type Remote (Authenticated) Affected Versions Versions before 8.6.8 Discoverer Yazar Abu-Nadi