Medium CVSS: 6.5 CVE-2025-24949 In JotUrl 2.0, is possible to bypass security requirements during the password change process.
Medium CVSS: 6.5 CVE-2025-24948 In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.