VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 11 of 31
  • CVE-2026-53517HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the…

  • CVE-2025-71335HigJun 25, 2026
    risk 0.46cvss 8.1epss 0.00

    Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains…

  • CVE-2026-43983HigMay 12, 2026
    risk 0.46cvss 8.1epss 0.00

    Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current…

  • CVE-2026-34503HigMar 31, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.

  • CVE-2025-15553HigMar 16, 2026
    risk 0.46cvss 7.1epss 0.00

    Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

  • CVE-2025-53896HigNov 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched in version 9.1.0.

  • CVE-2025-58437HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automatically generates a session token for a…

  • CVE-2025-50486HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50485HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50487HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.

  • CVE-2025-50484HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50491HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50488HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-31952HigJul 24, 2025
    risk 0.46cvss 7.1epss 0.00

    HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

  • CVE-2024-45033HigJan 8, 2025
    risk 0.46cvss 8.1epss 0.01

    Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user have not been cleared, leading to insufficient session…

  • CVE-2024-45187HigAug 23, 2024
    risk 0.46cvss 7.1epss 0.01

    Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server

  • CVE-2023-37504HigOct 19, 2023
    risk 0.46cvss 7.1epss 0.00

    HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the…

  • CVE-2022-41672HigOct 7, 2022
    risk 0.46cvss 8.1epss 0.01

    In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.

  • CVE-2021-3461HigApr 1, 2022
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

  • CVE-2022-24743HigMar 14, 2022
    risk 0.46cvss 7.1epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing token and unauthorized password…