CWE-620
Unverified Password Change
Description
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (92)
page 5 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-2543 | Low | 0.18 | 2.7 | 0.00 | Feb 16, 2026 | A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverified password change. The attack can be… | ||
| CVE-2025-47938 | Low | 0.18 | 3.8 | 0.00 | May 20, 2025 | TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current… | ||
| CVE-2025-46748 | — | Low | 0.18 | 2.7 | 0.00 | May 12, 2025 | An authenticated user attempting to change their password could do so without using the current password. | |
| CVE-2023-4465 | Low | 0.18 | 2.7 | 0.00 | Dec 29, 2023 | A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101,… | ||
| CVE-2024-47784 | Low | 0.17 | 2.6 | 0.00 | Apr 30, 2025 | Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier. | ||
| CVE-2024-2213 | Low | 0.14 | 3.3 | 0.00 | Jun 6, 2024 | An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for… | ||
| CVE-2026-12692 | Cri | 0.00 | 9.8 | 0.00 | Jul 17, 2026 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | ||
| CVE-2026-56305 | Hig | 0.00 | 8.3 | 0.00 | Jul 10, 2026 | Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock… | ||
| CVE-2026-44733 | Med | 0.00 | 5.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation flaw in the change password behavior allows… | ||
| CVE-2023-4381 | Med | 0.00 | 4.3 | 0.00 | Aug 16, 2023 | Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | ||
| CVE-2023-3069 | Cri | 0.00 | 9.8 | 0.01 | Jun 2, 2023 | Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2022-3152 | Hig | 0.00 | 8.8 | 0.01 | Sep 7, 2022 | Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. |
- risk 0.18cvss 2.7epss 0.00
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverified password change. The attack can be…
- risk 0.18cvss 3.8epss 0.00
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current…
- risk 0.18cvss 2.7epss 0.00
An authenticated user attempting to change their password could do so without using the current password.
- risk 0.18cvss 2.7epss 0.00
A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101,…
- risk 0.17cvss 2.6epss 0.00
Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.
- risk 0.14cvss 3.3epss 0.00
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for…
- risk 0.00cvss 9.8epss 0.00
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
- risk 0.00cvss 8.3epss 0.00
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock…
- risk 0.00cvss 5.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation flaw in the change password behavior allows…
- risk 0.00cvss 4.3epss 0.00
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- risk 0.00cvss 9.8epss 0.01
Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 8.8epss 0.01
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.