VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (309)

page 5 of 16
  • CVE-2026-26273CriFeb 13, 2026
    risk 0.57cvss 9.8epss 0.01

    Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset page. This allows any unauthenticated…

  • CVE-2025-64113CriDec 9, 2025
    risk 0.57cvss 9.8epss 0.01

    Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled…

  • CVE-2025-66225HigNov 29, 2025
    risk 0.57cvss 8.8epss 0.00

    OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After…

  • CVE-2025-50503HigAug 20, 2025
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without…

  • CVE-2024-12295HigMar 19, 2025
    risk 0.57cvss 8.8epss 0.00

    The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating their password through the…

  • CVE-2024-11103CriNov 28, 2024
    risk 0.57cvss 9.8epss 0.01

    The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for…

  • CVE-2024-45980HigSep 26, 2024
    risk 0.57cvss 8.8epss 0.00

    A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

  • CVE-2023-35717HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link Tapo C210 IP cameras. Authentication is not required to exploit this vulnerability. The…

  • CVE-2024-27899HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.00

    Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and…

  • CVE-2024-22454HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with…

  • CVE-2023-49589HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to…

  • CVE-2023-47107HigNov 8, 2023
    risk 0.57cvss 8.8epss 0.01

    PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL…

  • CVE-2023-31459HigMay 24, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not…

  • CVE-2021-31912HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

  • CVE-2020-25728HigSep 17, 2020
    risk 0.57cvss 8.8epss 0.01

    The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.

  • CVE-2017-18908CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.

  • CVE-2012-5618CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.01

    Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

  • CVE-2019-20004HigJan 5, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

  • CVE-2019-10270HigJun 21, 2019
    risk 0.57cvss 8.8epss 0.01

    An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset the password of another user. One only…

  • CVE-2019-11414HigApr 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.