CVE-2025-4644 — A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT) — CVE Database · The Intelligence Room