VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (328)

page 2 of 17
  • CVE-2022-50910CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account…

  • CVE-2025-50433CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

  • CVE-2025-12866CriNov 10, 2025
    risk 0.64cvss 9.8epss 0.01

    EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

  • CVE-2025-10127CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.01

    Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.

  • CVE-2025-32486CriSep 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.

  • CVE-2025-50594CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password.

  • CVE-2025-43932CriJul 7, 2025
    risk 0.64cvss 9.8epss 0.00

    JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

  • CVE-2025-43931CriJul 7, 2025
    risk 0.64cvss 9.8epss 0.00

    flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

  • CVE-2025-31380CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11.

  • CVE-2025-22144CriJan 13, 2025
    risk 0.64cvss 9.8epss 0.01

    NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code…

  • CVE-2024-11350CriJan 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password()…

  • CVE-2024-53552CriDec 10, 2024
    risk 0.64cvss 9.8epss 0.01

    CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

  • CVE-2024-48428CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.

  • CVE-2024-8878CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

  • CVE-2024-38287CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.

  • CVE-2024-38468CriJun 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

  • CVE-2024-5404CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.

  • CVE-2023-43902CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

  • CVE-2023-36487CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

  • CVE-2023-30466CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this…