VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (309)

page 1 of 16
  • CVE-2023-7028CriKEVJan 12, 2024
    risk 0.88cvss 10.0epss 0.95

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could…

  • CVE-2012-5686CriFeb 4, 2020
    risk 0.67cvss 9.8epss 0.05

    ZPanel 10.0.1 has insufficient entropy for its password reset process.

  • CVE-2017-17097CriJan 2, 2018
    risk 0.67cvss 9.8epss 0.07

    gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to…

  • CVE-2017-7615HigApr 16, 2017
    risk 0.67cvss 8.8epss 0.91

    MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

  • CVE-2025-6216CriJun 21, 2025
    risk 0.66cvss 9.8epss 0.35

    Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-4320CriJan 23, 2026
    risk 0.65cvss 10.0epss 0.00

    Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through…

  • CVE-2025-63314CriJan 12, 2026
    risk 0.65cvss 10.0epss 0.00

    A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

  • CVE-2025-47646CriMay 23, 2025
    risk 0.65cvss 9.8epss 0.26

    Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

  • CVE-2026-37106CriJun 30, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a…

  • CVE-2026-12417CriJun 24, 2026
    risk 0.64cvss 9.8epss 0.00

    The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via…

  • CVE-2026-12416CriJun 24, 2026
    risk 0.64cvss 9.8epss 0.01

    The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no…

  • CVE-2026-32865CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.00

    OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security…

  • CVE-2026-28213CriFeb 26, 2026
    risk 0.64cvss 9.8epss 0.00

    EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated…

  • CVE-2022-50910CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account…

  • CVE-2025-50433CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

  • CVE-2025-12866CriNov 10, 2025
    risk 0.64cvss 9.8epss 0.01

    EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

  • CVE-2025-10127CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

  • CVE-2025-32486CriSep 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.

  • CVE-2025-50594CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password.