VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (309)

page 10 of 16
  • CVE-2025-1570HigFeb 28, 2025
    risk 0.46cvss 8.1epss 0.00

    The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and…

  • CVE-2024-9302HigOct 25, 2024
    risk 0.46cvss 8.1epss 0.01

    The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not…

  • CVE-2024-6125HigJun 19, 2024
    risk 0.46cvss 8.1epss 0.00

    The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit. This makes it…

  • CVE-2023-4214HigNov 18, 2023
    risk 0.46cvss 8.1epss 0.01

    The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

  • CVE-2014-6412HigApr 12, 2018
    risk 0.46cvss 8.1epss 0.05

    WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

  • CVE-2017-5594HigJan 25, 2017
    risk 0.45cvss 7.5epss 0.07

    An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.

  • CVE-2023-31287HigApr 27, 2023
    risk 0.44cvss 7.8epss 0.00

    An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the…

  • CVE-2022-22691MedJan 18, 2022
    risk 0.44cvss 6.8epss 0.01

    The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the…

  • CVE-2019-12476MedJun 17, 2019
    risk 0.44cvss 6.8epss 0.02

    An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence…

  • CVE-2017-2614MedJul 27, 2018
    risk 0.44cvss 6.8epss 0.00

    When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining…

  • CVE-2026-7459HigMay 30, 2026
    risk 0.42cvss 7.5epss 0.01

    The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints…

  • CVE-2025-56748MedOct 15, 2025
    risk 0.42cvss 6.4epss 0.00

    Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

  • CVE-2024-12604MedMar 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse. This issue affects Tap&Sign App:…

  • CVE-2023-3007MedMay 31, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Handler. The manipulation of the argument sid leads to weak…

  • CVE-2022-24892MedApr 28, 2022
    risk 0.42cvss 6.4epss 0.01

    Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for an attacker to take over the victim's…

  • CVE-2022-0777HigMar 1, 2022
    risk 0.42cvss 7.5epss 0.01

    Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2021-44839MedJan 18, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset…

  • CVE-2021-33321HigAug 3, 2021
    risk 0.42cvss 7.5epss 0.01

    Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.

  • CVE-2019-15749MedOct 7, 2019
    risk 0.42cvss 6.5epss 0.01

    SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change…

  • CVE-2018-12315MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.