CWE-640— Weak Password Recovery Mechanism for Forgotten Password
245 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 3 of 5
- CVE-2022-29933HIGHCVSS 8.8EG 8.82022-05-09
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the passw…
- CVE-2022-30332MEDIUMCVSS 5.3EG 5.32023-01-10
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows re…
- CVE-2022-34530MEDIUMCVSS 5.3EG 5.32022-08-01
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
- CVE-2022-3485CRITICALCVSS 9.8EG 9.82022-12-12
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
- CVE-2022-37300CRITICALCVSS 9.8EG 9.82022-09-12
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Ex…
- CVE-2022-42807MEDIUMCVSS 4.3EG 4.32023-06-23
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key
- CVE-2022-44004CRITICALCVSS 9.8EG 9.82022-11-16
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
- CVE-2022-45637CRITICALCVSS 9.8EG 9.82023-03-21
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
- CVE-2022-45782HIGHCVSS 8.8EG 9.82023-02-01
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.
- CVE-2022-47377CRITICALCVSS 9.8EG 9.82022-12-16
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery m…
- CVE-2022-47697CRITICALCVSS 9.8EG 9.82023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.
- CVE-2022-50910CRITICALCVSS 9.8EG 7.52026-01-13
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset t…
- CVE-2023-0352CRITICALCVSS 9.1EG 9.12023-03-13
The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.
- CVE-2023-26615HIGHCVSS 7.5EG 7.52023-06-28
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
- CVE-2023-28202MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app firewall setting may not take effect after exiting the Settings app.
- CVE-2023-28821MEDIUMCVSS 5.3EG 5.32023-04-28
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
- CVE-2023-29145HIGHCVSS 7.8EG 7.82023-06-30
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an execut…
- CVE-2023-3007MEDIUMCVSS 6.5EG 6.52023-05-31
A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Handler. The manipulat…
- CVE-2023-30466CRITICALCVSS 9.8EG 9.82023-04-28
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remo…
- CVE-2023-31287HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be…
- CVE-2023-31459HIGHCVSS 8.8EG 8.82023-05-24
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, becaus…
- CVE-2023-3222HIGHCVSS 7.5EG 7.52023-09-04
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could…
- CVE-2023-34357HIGHCVSS 7.8EG 7.82023-09-07
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration d…
- CVE-2023-35134HIGHCVSS 7.4EG 7.42023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.
- CVE-2023-35717HIGHCVSS 8.8EG 8.82024-05-03
TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link Tapo C210 IP cameras. Authentication is not require…
- CVE-2023-36487CRITICALCVSS 9.8EG 9.82023-06-29
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
- CVE-2023-4096HIGHCVSS 8.6EG 8.62023-09-19
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate…
- CVE-2023-4214HIGHCVSS 8.1EG 8.12023-11-18
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or…
- CVE-2023-42481HIGHCVSS 8.1EG 8.12023-12-12
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP…
- CVE-2023-43650HIGHCVSS 8.2EG 8.22023-09-27
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer provides a feature allowing users to reset forgotten passwo…
- CVE-2023-44399MEDIUMCVSS 5.3EG 5.32023-10-10
ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. While this settings…
- CVE-2023-4448MEDIUMCVSS 6.3EG 6.32023-08-21
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password rec…
- CVE-2023-46138LOWCVSS 3.7EG 3.72023-10-31
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycompany[.]com`, and users reset their pass…
- CVE-2023-47107HIGHCVSS 8.8EG 8.82023-11-08
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It …
- CVE-2023-49097HIGHCVSS 8.1EG 8.12023-11-30
ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this hea…
- CVE-2023-49589HIGHCVSS 8.8EG 8.82024-01-10
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An …
- CVE-2023-50172MEDIUMCVSS 5.3EG 5.32024-01-10
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pas…
- CVE-2023-5296MEDIUMCVSS 4.3EG 4.32023-09-29
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation le…
- CVE-2023-53958HIGHCVSS 7.5EG 7.52025-12-19
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sen…
- CVE-2023-5840HIGHCVSS 8.8EG 6.52023-10-29
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
- CVE-2023-5959MEDIUMCVSS 4.3EG 4.32023-11-11
A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak passwo…
- CVE-2023-7028CRITICALCVSS 10.0EG 10.0⚠ KEV2024-01-12
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which …
- CVE-2023-7264HIGHCVSS 8.1EG 8.12024-06-11
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of …
- CVE-2024-0186LOWCVSS 3.7EG 3.72024-01-02
A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unknown function of the file /user/index/findpass?do=4 of the component HTTP POST Request Handler. The manipulation leads t…
- CVE-2024-0425MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be in…
- CVE-2024-0491MEDIUMCVSS 5.3EG 5.32024-01-13
A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is…
- CVE-2024-11103CRITICALCVSS 9.8EG 9.82024-11-28
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their p…
- CVE-2024-11350CRITICALCVSS 9.8EG 9.82025-01-08
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password t…
- CVE-2024-12295HIGHCVSS 8.8EG 8.82025-03-19
The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating…
- CVE-2024-12604MEDIUMCVSS 6.5EG 7.32025-03-10
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misus…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →