CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Description
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-50
CVEs mapped to this weakness (328)
page 1 of 17| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-7028 | Cri | 0.88 | 10.0 | 0.95 | KEV | Jan 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could… | |
| CVE-2019-18818 | Cri | 0.75 | 9.8 | 0.98 | Nov 7, 2019 | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js. | ||
| CVE-2012-5686 | Cri | 0.67 | 9.8 | 0.05 | Feb 4, 2020 | ZPanel 10.0.1 has insufficient entropy for its password reset process. | ||
| CVE-2017-17097 | Cri | 0.67 | 9.8 | 0.07 | Jan 2, 2018 | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to… | ||
| CVE-2017-7615 | Hig | 0.67 | 8.8 | 0.91 | Apr 16, 2017 | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. | ||
| CVE-2025-6216 | Cri | 0.66 | 9.8 | 0.48 | Jun 21, 2025 | Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists… | ||
| CVE-2025-4320 | Cri | 0.65 | 10.0 | 0.01 | Jan 23, 2026 | Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through… | ||
| CVE-2025-63314 | Cri | 0.65 | 10.0 | 0.00 | Jan 12, 2026 | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack. | ||
| CVE-2025-47646 | Cri | 0.65 | 9.8 | 0.25 | May 23, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13. | ||
| CVE-2026-71625 | Cri | 0.64 | 9.8 | 0.01 | Sep 4, 2026 | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | ||
| CVE-2026-77264 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic… | ||
| CVE-2026-15689 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2026 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes… | ||
| CVE-2026-12949 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2026 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter… | ||
| CVE-2026-66691 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | ||
| CVE-2026-61967 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||
| CVE-2026-12571 | Cri | 0.64 | 9.8 | 0.03 | Aug 11, 2026 | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. | ||
| CVE-2026-13019 | Cri | 0.64 | 9.8 | 0.01 | Jul 7, 2026 | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for… | ||
| CVE-2026-37106 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2026 | An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a… | ||
| CVE-2026-12417 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via… | ||
| CVE-2026-12416 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2026 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no… |
- risk 0.88cvss 10.0epss 0.95
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could…
- risk 0.75cvss 9.8epss 0.98
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
- risk 0.67cvss 9.8epss 0.05
ZPanel 10.0.1 has insufficient entropy for its password reset process.
- risk 0.67cvss 9.8epss 0.07
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to…
- risk 0.67cvss 8.8epss 0.91
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
- risk 0.66cvss 9.8epss 0.48
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists…
- risk 0.65cvss 10.0epss 0.01
Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This issue affects Sufirmam: through…
- risk 0.65cvss 10.0epss 0.00
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.
- risk 0.65cvss 9.8epss 0.25
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.
- risk 0.64cvss 9.8epss 0.01
An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component
- risk 0.64cvss 9.8epss 0.01
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic…
- risk 0.64cvss 9.8epss 0.01
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes…
- risk 0.64cvss 9.8epss 0.01
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
- risk 0.64cvss 9.8epss 0.03
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
- risk 0.64cvss 9.8epss 0.01
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for…
- risk 0.64cvss 9.8epss 0.01
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a…
- risk 0.64cvss 9.8epss 0.01
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via…
- risk 0.64cvss 9.8epss 0.01
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no…