CWE-620
Unverified Password Change
Description
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (92)
page 3 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-3607 | Hig | 0.50 | 8.8 | 0.00 | Apr 24, 2025 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it… | ||
| CVE-2022-21935 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2022 | A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change. | ||
| CVE-2025-67719 | Hig | 0.48 | — | 0.00 | Dec 11, 2025 | Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to… | ||
| CVE-2026-73292 | Hig | 0.47 | 8.3 | 0.00 | Aug 12, 2026 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an… | ||
| CVE-2026-54801 | — | Hig | 0.47 | 7.2 | 0.00 | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account… | |
| CVE-2025-71328 | Hig | 0.47 | 8.3 | 0.00 | Jun 25, 2026 | Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not… | ||
| CVE-2025-71337 | Hig | 0.47 | 8.3 | 0.00 | Jun 23, 2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profile endpoint without… | ||
| CVE-2026-42084 | Hig | 0.46 | 8.1 | 0.00 | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by… | ||
| CVE-2026-40588 | Hig | 0.46 | 8.1 | 0.00 | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid… | ||
| CVE-2026-27757 | Hig | 0.46 | 7.1 | 0.00 | Feb 27, 2026 | SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to… | ||
| CVE-2025-61132 | Hig | 0.46 | 7.1 | 0.00 | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links… | ||
| CVE-2023-4214 | Hig | 0.46 | 8.1 | 0.01 | Nov 18, 2023 | The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit. | ||
| CVE-2026-17599 | Med | 0.45 | — | 0.00 | Aug 7, 2026 | Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding… | ||
| CVE-2026-46623 | hig | 0.45 | — | — | Jun 26, 2026 | ## Summary **Description** An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account.… | ||
| CVE-2025-59808 | Med | 0.44 | 6.8 | 0.00 | Dec 9, 2025 | An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR… | ||
| CVE-2022-2930 | Hig | 0.44 | 7.8 | 0.00 | Aug 22, 2022 | Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3. | ||
| CVE-2025-46389 | — | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2025 | CWE-620: Unverified Password Change | |
| CVE-2024-41796 | Med | 0.42 | 6.5 | 0.00 | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated… | ||
| CVE-2023-25931 | Med | 0.42 | 6.4 | 0.00 | Mar 1, 2023 | Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy… | ||
| CVE-2021-34786 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2021 | Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. |
- risk 0.50cvss 8.8epss 0.00
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it…
- risk 0.49cvss 7.5epss 0.01
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
- risk 0.48cvss —epss 0.00
Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to…
- risk 0.47cvss 8.3epss 0.00
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an…
- risk 0.47cvss 7.2epss 0.00
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account…
- risk 0.47cvss 8.3epss 0.00
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not…
- risk 0.47cvss 8.3epss 0.00
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profile endpoint without…
- risk 0.46cvss 8.1epss 0.00
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by…
- risk 0.46cvss 8.1epss 0.00
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid…
- risk 0.46cvss 7.1epss 0.00
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to…
- risk 0.46cvss 7.1epss 0.00
A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links…
- risk 0.46cvss 8.1epss 0.01
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.
- risk 0.45cvss —epss 0.00
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding…
- risk 0.45cvss —epss —
## Summary **Description** An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account.…
- risk 0.44cvss 6.8epss 0.00
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR…
- risk 0.44cvss 7.8epss 0.00
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
- risk 0.42cvss 6.5epss 0.00
CWE-620: Unverified Password Change
- risk 0.42cvss 6.5epss 0.00
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated…
- risk 0.42cvss 6.4epss 0.00
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy…
- risk 0.42cvss 6.5epss 0.01
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.