VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (640)

page 31 of 32
  • CVE-2026-42172LowJul 7, 2026
    risk 0.00cvss 3.1epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until manually revoked. This issue is fixed in version…

  • CVE-2026-43918HigJul 6, 2026
    risk 0.00cvss —epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client…

  • CVE-2026-14725MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and…

  • CVE-2025-36359HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.

  • CVE-2026-27968MedFeb 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a result, an expired deploy token with the…

  • CVE-2026-25476HigFeb 25, 2026
    risk 0.00cvss 7.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1`…

  • CVE-2025-62174LowOct 13, 2025
    risk 0.00cvss 3.5epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions…

  • CVE-2025-54592CriSep 29, 2025
    risk 0.00cvss 9.8epss 0.01

    FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if a new session were to…

  • CVE-2025-59841CriSep 25, 2025
    risk 0.00cvss 9.8epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users can continue to access protected endpoints, such as /api/profile, even after logging out. CSRF…

  • CVE-2025-59335HigSep 22, 2025
    risk 0.00cvss 7.1epss 0.00

    CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account,…

  • CVE-2025-35433MedSep 17, 2025
    risk 0.00cvss 5.0epss 0.00

    CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.

  • CVE-2025-24896HigFeb 11, 2025
    risk 0.00cvss 8.1epss 0.01

    Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie for authentication purposes in Bull Dashboard, but this remains undeleted even after logout is…

  • CVE-2024-55603MedDec 19, 2024
    risk 0.00cvss 6.5epss 0.01

    Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard implements a cutom session handler (`app/Core/Session/SessionHandler.php`), to store the session data…

  • CVE-2024-52553HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

  • CVE-2024-25619LowFeb 14, 2024
    risk 0.00cvss 3.1epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the Access Tokens had also been destroyed, this could have posed security risks to users by allowing an application…

  • CVE-2024-22403LowJan 18, 2024
    risk 0.00cvss 3.0epss 0.00

    Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10…

  • CVE-2023-49091HigNov 29, 2023
    risk 0.00cvss 8.8epss 0.01

    Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid and not expiring after log out. This…

  • CVE-2023-5889HigNov 1, 2023
    risk 0.00cvss 8.2epss 0.00

    Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5838CriOct 29, 2023
    risk 0.00cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

  • CVE-2023-45659LowOct 17, 2023
    risk 0.00cvss 3.6epss 0.00

    Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This…