CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
305 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 4 of 7
- CVE-2023-42481HIGHCVSS 8.1EG 8.12023-12-12
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP…
- CVE-2023-43650HIGHCVSS 7.4EG 7.42023-09-27
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer provides a feature allowing users to reset forgotten passwo…
- CVE-2023-44399MEDIUMCVSS 5.3EG 5.32023-10-10
ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. While this settings…
- CVE-2023-4448CRITICALCVSS 9.8EG 9.82023-08-21
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password rec…
- CVE-2023-46138MEDIUMCVSS 5.3EG 5.32023-10-31
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycompany[.]com`, and users reset their pass…
- CVE-2023-47107HIGHCVSS 8.8EG 8.82023-11-08
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It …
- CVE-2023-49097HIGHCVSS 8.8EG 8.82023-11-30
ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this hea…
- CVE-2023-49589HIGHCVSS 8.8EG 8.82024-01-10
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An …
- CVE-2023-50172MEDIUMCVSS 5.3EG 5.32024-01-10
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pas…
- CVE-2023-5296HIGHCVSS 7.5EG 7.52023-09-29
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation le…
- CVE-2023-53958HIGHCVSS 7.5EG 7.52025-12-19
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sen…
- CVE-2023-5840HIGHCVSS 8.8EG 8.82023-10-29
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
- CVE-2023-5959MEDIUMCVSS 4.3EG 4.32023-11-11
A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak passwo…
- CVE-2023-7028CRITICALCVSS 10.0EG 10.0⚠ KEV2024-01-12
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which …
- CVE-2023-7264HIGHCVSS 8.1EG 8.12024-06-11
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of …
- CVE-2024-0186HIGHCVSS 8.1EG 8.12024-01-02
A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unknown function of the file /user/index/findpass?do=4 of the component HTTP POST Request Handler. The manipulation leads t…
- CVE-2024-0425MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be in…
- CVE-2024-0491MEDIUMCVSS 5.3EG 5.32024-01-13
A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is…
- CVE-2024-11103CRITICALCVSS 9.8EG 9.82024-11-28
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their p…
- CVE-2024-11350CRITICALCVSS 9.8EG 9.82025-01-08
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password t…
- CVE-2024-12295HIGHCVSS 8.8EG 8.82025-03-19
The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating…
- CVE-2024-12604HIGHCVSS 6.5EG 7.32025-03-10
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misus…
- CVE-2024-22454HIGHCVSS 8.8EG 8.82024-02-13
Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized …
- CVE-2024-2463HIGHCVSS 8.0EG 8.02024-03-21
Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.
- CVE-2024-24903HIGHCVSS 8.0EG 8.02024-03-01
Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unaut…
- CVE-2024-27899HIGHCVSS 8.8EG 8.82024-04-09
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause…
- CVE-2024-2862CRITICALCVSS 9.1EG 9.12024-03-25
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
- CVE-2024-32642HIGHCVSS 8.8EG 8.82025-12-03
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8…
- CVE-2024-33530HIGHCVSS 7.5EG 7.52024-05-02
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
- CVE-2024-36407LOWCVSS 3.7EG 3.72024-06-10
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new passw…
- CVE-2024-38287CRITICALCVSS 9.8EG 9.82024-07-25
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit v…
- CVE-2024-38468CRITICALCVSS 9.8EG 9.82024-06-16
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
- CVE-2024-42915HIGHCVSS 8.0EG 8.02024-08-23
A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' p…
- CVE-2024-43190MEDIUMCVSS 5.9EG 5.92025-07-07
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
- CVE-2024-45670MEDIUMCVSS 5.6EG 5.62024-11-14
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.
- CVE-2024-45980HIGHCVSS 8.8EG 8.82024-09-26
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compr…
- CVE-2024-47547CRITICALCVSS 9.4EG 9.42024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.
- CVE-2024-48428CRITICALCVSS 9.8EG 9.82024-10-25
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
- CVE-2024-50356UnratedEG 0.02024-10-31
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even tho…
- CVE-2024-5277HIGHCVSS 7.5EG 7.52024-06-06
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the p…
- CVE-2024-53552CRITICALCVSS 9.8EG 9.82024-12-10
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
- CVE-2024-5404CRITICALCVSS 9.8EG 9.82024-06-03
An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.
- CVE-2024-6125HIGHCVSS 8.1EG 8.12024-06-19
The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to reset the password has…
- CVE-2024-6203HIGHCVSS 8.3EG 8.32024-08-06
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.…
- CVE-2024-8692MEDIUMCVSS 5.3EG 5.32024-09-11
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The explo…
- CVE-2024-8878CRITICALCVSS 9.8EG 9.82024-09-25
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
- CVE-2024-9302HIGHCVSS 8.1EG 8.12024-10-25
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password()…
- CVE-2024-9305HIGHCVSS 8.1EG 8.12024-10-16
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() fun…
- CVE-2024-9907LOWCVSS 3.7EG 3.72024-10-13
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation lead…
- CVE-2025-0331MEDIUMCVSS 5.3EG 5.32025-01-09
A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. T…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →