VYPR

CWE-384

Session Fixation

CompoundIncomplete

Description

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-31 · CAPEC-39 · CAPEC-59 · CAPEC-60 · CAPEC-61

CVEs mapped to this weakness (435)

page 21 of 22
  • CVE-2025-0253LowJul 25, 2025
    risk 0.13cvss 2.0epss 0.00

    HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.

  • CVE-2025-1412LowFeb 24, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

  • CVE-2026-16496HigJul 28, 2026
    risk 0.00cvss 8.9epss 0.00

    The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This…

  • CVE-2021-32088CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.

  • CVE-2026-14609MedJul 3, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of…

  • CVE-2026-56224MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in…

  • CVE-2026-35095MedJun 30, 2026
    risk 0.00cvss epss 0.00

    KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session ID for a victim and later hijack the…

  • CVE-2026-12581HigJun 22, 2026
    risk 0.00cvss 7.5epss 0.00

    EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

  • CVE-2025-59841CriSep 25, 2025
    risk 0.00cvss 9.8epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users can continue to access protected endpoints, such as /api/profile, even after logging out. CSRF…

  • CVE-2025-53102CriJul 29, 2025
    risk 0.00cvss 9.8epss 0.00

    Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The…

  • CVE-2025-29928HigMar 28, 2025
    risk 0.00cvss 8.0epss 0.00

    authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage (which is a non-default setting), deleting sessions via the Web Interface or the API would not revoke the session and…

  • CVE-2021-3740MedNov 15, 2024
    risk 0.00cvss 6.8epss 0.00

    A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker…

  • CVE-2024-52553HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

  • CVE-2024-31221MedApr 8, 2024
    risk 0.00cvss 5.9epss 0.01

    Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0…

  • CVE-2023-4649MedAug 31, 2023
    risk 0.00cvss 5.4epss 0.00

    Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.

  • CVE-2023-3394MedJun 23, 2023
    risk 0.00cvss 5.4epss 0.01

    Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.

  • CVE-2022-31888HigApr 5, 2023
    risk 0.00cvss 8.8epss 0.01

    Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

  • CVE-2020-15679HigDec 22, 2022
    risk 0.00cvss 7.6epss 0.00

    An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as that user. This issue is limited to cases where attacker and victim are sharing…

  • CVE-2022-2820HigAug 15, 2022
    risk 0.00cvss 7.0epss 0.01

    Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.

  • CVE-2022-24781HigMar 24, 2022
    risk 0.00cvss 7.1epss 0.01

    Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session. This issue is patched in version 1.1.0. No known…