Hi,
I found a very dangerous problem:
I have a login with email address.
When I am a superuser and I click forgot password and enter my email address and security code, then I get an error notice: "SQL error".
I get an email with a new password. But with this new password I cannot login. I have to use the old one.
(The problem is, when I really forgot the old password, I am out!)
I tried this as a registered user, then I have no SQL error.