CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
580 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 9 of 12
- CVE-2025-31962LOWCVSS 4.3EG 2.02026-01-07
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
- CVE-2025-32441MEDIUMCVSS 4.2EG 4.22025-05-07
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that sess…
- CVE-2025-33005MEDIUMCVSS 6.3EG 6.32025-06-01
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-35433MEDIUMCVSS 5.0EG 5.02025-09-17
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.
- CVE-2025-36040MEDIUMCVSS 6.5EG 6.52025-07-31
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.
- CVE-2025-36063MEDIUMCVSS 6.5EG 6.32026-01-20
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-36065MEDIUMCVSS 6.5EG 6.32026-01-20
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-36359HIGHCVSS 6.5EG 8.12026-06-30
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-36360MEDIUMCVSS 5.0EG 5.02025-12-15
IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-IP …
- CVE-2025-36376HIGHCVSS 8.8EG 8.82026-02-17
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-36377HIGHCVSS 8.8EG 8.82026-02-17
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
- CVE-2025-3930MEDIUMCVSS 6.3EG 6.32025-10-16
Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is…
- CVE-2025-40566HIGHCVSS 8.8EG 8.82025-05-13
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow…
- CVE-2025-42602HIGHCVSS 8.2EG 8.22025-04-23
This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could exploit this vulnerability by intercepting and manipulating t…
- CVE-2025-43819MEDIUMCVSS 6.5EG 6.52025-09-24
A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is…
- CVE-2025-4407MEDIUMCVSS 6.7EG 6.72025-06-30
Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.
- CVE-2025-4528MEDIUMCVSS 4.3EG 4.32025-05-11
A weakness has been identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mit…
- CVE-2025-46336MEDIUMCVSS 4.2EG 4.22025-05-08
Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the attacker can acquire a session cookie (already a major issue), …
- CVE-2025-46344MEDIUMCVSS 4.9EG 4.92025-04-29
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, …
- CVE-2025-4643MEDIUMCVSS 6.3EG 6.32025-08-29
Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can…
- CVE-2025-46741MEDIUMCVSS 5.7EG 5.72025-05-12
A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.
- CVE-2025-4677MEDIUMCVSS 6.5EG 6.52026-01-07
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
- CVE-2025-46815HIGHCVSS 8.0EG 8.02025-05-06
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the cli…
- CVE-2025-4754LOWCVSS 2.3EG 2.32025-06-17
Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex. This issue affects ash_aut…
- CVE-2025-48061MEDIUMCVSS 5.6EG 5.62025-05-22
wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logged out of the Wire webapp, could have been automatically logg…
- CVE-2025-48929MEDIUMCVSS 4.0EG 4.02025-05-28
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.
- CVE-2025-49152HIGHCVSS 8.7EG 8.72025-06-25
The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.
- CVE-2025-50484HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
- CVE-2025-50485HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.
- CVE-2025-50486HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.
- CVE-2025-50487HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.
- CVE-2025-50488HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.
- CVE-2025-50491HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.
- CVE-2025-52661LOWCVSS 5.3EG 2.42026-01-19
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.
- CVE-2025-53642MEDIUMCVSS 4.8EG 4.82025-07-11
haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulner…
- CVE-2025-53826CRITICALCVSS 9.8EG 9.82025-07-15
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that…
- CVE-2025-53896HIGHCVSS 7.1EG 7.12025-11-29
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue ha…
- CVE-2025-54547MEDIUMCVSS 5.3EG 5.32025-10-29
On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
- CVE-2025-54592CRITICALCVSS 9.8EG 9.82025-09-29
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused b…
- CVE-2025-55162MEDIUMCVSS 6.3EG 6.32025-09-03
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, 1.34.0 through 1.34.4 and 1.35.0, insufficient Session Expiration in the …
- CVE-2025-55254LOWCVSS 3.7EG 3.72025-12-17
Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.
- CVE-2025-55264MEDIUMCVSS 5.5EG 5.52026-03-26
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a session, then they can maintain control over the account despite the password change leading to account takeover.
- CVE-2025-55278HIGHCVSS 8.1EG 8.12025-11-05
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentia…
- CVE-2025-55705HIGHCVSS 9.8EG 7.32026-01-22
This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging ses…
- CVE-2025-56643CRITICALCVSS 9.1EG 9.12025-11-18
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects ses…
- CVE-2025-57735CRITICALCVSS 9.1EG 9.12026-04-09
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at…
- CVE-2025-57766MEDIUMCVSS 4.8EG 4.82025-09-08
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where attackers who have obtained …
- CVE-2025-58352MEDIUMCVSS 6.5EG 6.52025-09-05
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the s…
- CVE-2025-58437HIGHCVSS 8.1EG 8.12025-09-06
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be compromised through insecure session handling in prebuilt workspaces. Coder automati…
- CVE-2025-59335HIGHCVSS 7.1EG 7.12025-09-22
CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a locat…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →