CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
580 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 10 of 12
- CVE-2025-59786CRITICALCVSS 9.8EG 9.82026-03-04
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
- CVE-2025-59841CRITICALCVSS 9.8EG 9.82025-09-25
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users can continue to access protected endpoints, such as /api/pr…
- CVE-2025-61775MEDIUMCVSS 6.9EG 6.92025-10-13
Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unexpired email confirmation links can be reused multiple times to send repeated confirmation emails to a verified email ad…
- CVE-2025-62174LOWCVSS 3.5EG 3.52025-10-13
Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts mo…
- CVE-2025-62329MEDIUMCVSS 5.0EG 5.02025-12-16
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized …
- CVE-2025-62340MEDIUMCVSS 5.3EG 5.32026-06-17
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
- CVE-2025-62631MEDIUMCVSS 5.6EG 5.62025-12-09
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an…
- CVE-2025-62781MEDIUMCVSS 5.0EG 5.02025-10-27
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except fo…
- CVE-2025-63226MEDIUMCVSS 5.7EG 5.72025-11-18
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the …
- CVE-2025-64386HIGHCVSS 7.7EG 7.72025-10-31
The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal …
- CVE-2025-64708MEDIUMCVSS 5.3EG 5.32025-11-19
authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions, invitations were considered valid regardless if they are expired or not, thus relying on background tasks to clean up …
- CVE-2025-65430MEDIUMCVSS 5.4EG 5.42025-12-15
An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was still active had no effect. Fixed the access/refresh tokens are now rejected.
- CVE-2025-65883HIGHCVSS 8.4EG 8.42025-12-04
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session inva…
- CVE-2025-66223HIGHCVSS 8.4EG 8.42025-11-29
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitati…
- CVE-2025-66289HIGHCVSS 8.8EG 8.82025-11-29
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies t…
- CVE-2025-66483MEDIUMCVSS 6.3EG 6.32026-04-01
IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-68954MEDIUMCVSS 5.4EG 5.42026-01-06
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access ov…
- CVE-2025-71335HIGHCVSS 8.1EG 8.12026-06-25
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session tok…
- CVE-2026-0971MEDIUMCVSS 4.3EG 4.32026-04-21
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
- CVE-2026-1163MEDIUMCVSS 4.1EG 4.12026-04-08
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This…
- CVE-2026-1190LOWCVSS 3.1EG 3.12026-01-26
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationDat…
- CVE-2026-1272LOWCVSS 2.7EG 2.72026-04-23
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.
- CVE-2026-12772MEDIUMCVSS 6.3EG 6.32026-06-21
A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulati…
- CVE-2026-12796MEDIUMCVSS 6.3EG 6.32026-06-21
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation…
- CVE-2026-1435CRITICALCVSS 9.8EG 9.82026-02-18
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but d…
- CVE-2026-14725MEDIUMCVSS 6.3EG 6.32026-07-05
A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. T…
- CVE-2026-15967HIGHCVSS 7.5EG 7.52026-07-23
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
- CVE-2026-16206MEDIUMCVSS 6.3EG 6.32026-07-19
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attac…
- CVE-2026-1815MEDIUMCVSS 5.7EG 5.72026-05-21
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13.
- CVE-2026-1842MEDIUMCVSS 6.2EG 6.22026-02-20
HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and failed to invalidate previously issued access tokens when a refresh token was used. Because refresh tokens have a signifi…
- CVE-2026-20748HIGHCVSS 8.6EG 7.32026-03-06
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables s…
- CVE-2026-20895HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-21622CRITICALCVSS 9.8EG 9.82026-03-05
Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the "Reset your password" flow do not expire. When a user reque…
- CVE-2026-22706MEDIUMCVSS 6.5EG 6.52026-05-14
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidati…
- CVE-2026-24472MEDIUMCVSS 5.3EG 5.32026-01-27
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. …
- CVE-2026-24667MEDIUMCVSS 5.0EG 5.02026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, pote…
- CVE-2026-24669HIGHCVSS 7.8EG 7.82026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token after it has already …
- CVE-2026-24894HIGHCVSS 7.5EG 7.52026-02-12
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to…
- CVE-2026-24912HIGHCVSS 8.6EG 7.32026-03-06
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables s…
- CVE-2026-25476HIGHCVSS 7.5EG 7.52026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in t…
- CVE-2026-25711HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-25720MEDIUMCVSS 5.4EG 5.42026-04-24
A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker w…
- CVE-2026-25778HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-26060HIGHCVSS 8.8EG 8.82026-03-27
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user changes their password. As a result, …
- CVE-2026-26290CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-26342CRITICALCVSS 9.8EG 9.82026-02-24
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exp…
- CVE-2026-27575CRITICALCVSS 9.1EG 9.12026-02-25
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active session…
- CVE-2026-27647CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-27649HIGHCVSS 6.5EG 7.32026-03-20
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables …
- CVE-2026-27652HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →