CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
664 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 1 of 14
- CVE-2024-8888CRITICALCVSS 10.0EG 10.02024-09-18
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token the…
- CVE-2026-79313CRITICALCVSS 9.8EG 9.82026-09-22
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expir…
- CVE-2026-82311CRITICALCVSS 9.8EG 9.82026-09-16
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session…
- CVE-2026-84480CRITICALCVSS 9.8EG 9.82026-09-01
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any tim…
- CVE-2026-14950CRITICALCVSS 9.8EG 9.82026-08-20
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and m…
- CVE-2026-15967CRITICALCVSS 9.8EG 9.82026-07-23
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
- CVE-2026-28564CRITICALCVSS 9.8EG 9.82026-07-10
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are reco…
- CVE-2026-46455CRITICALCVSS 9.8EG 9.82026-07-06
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) with only the subj…
- CVE-2026-21622CRITICALCVSS 9.8EG 9.82026-03-05
Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password reset tokens generated via the "Reset your password" flow do not expire. When a user reque…
- CVE-2025-59786CRITICALCVSS 9.8EG 9.82026-03-04
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.
- CVE-2026-27647CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-26290CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-26342CRITICALCVSS 9.8EG 9.82026-02-24
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exp…
- CVE-2026-1435CRITICALCVSS 9.8EG 9.82026-02-18
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but d…
- CVE-2025-55705CRITICALCVSS 9.8EG 9.82026-01-22
This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charging station ID. This can result in unauthorized access, data inconsistency, or potential manipulation of charging ses…
- CVE-2024-13996CRITICALCVSS 9.8EG 9.82025-10-30
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained…
- CVE-2025-54592CRITICALCVSS 9.8EG 9.82025-09-29
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused b…
- CVE-2025-59841CRITICALCVSS 9.8EG 9.82025-09-25
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users can continue to access protected endpoints, such as /api/pr…
- CVE-2025-53826CRITICALCVSS 9.8EG 9.82025-07-15
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that…
- CVE-2025-4528CRITICALCVSS 9.8EG 9.82025-05-11
A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates t…
- CVE-2024-13280CRITICALCVSS 9.8EG 9.82025-01-09
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.
- CVE-2024-43685CRITICALCVSS 9.8EG 9.82024-10-04
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
- CVE-2024-42447CRITICALCVSS 9.8EG 9.82024-08-05
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented…
- CVE-2024-29401CRITICALCVSS 9.8EG 9.82024-03-26
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
- CVE-2024-25718CRITICALCVSS 9.8EG 9.82024-02-11
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.
- CVE-2023-49091CRITICALCVSS 9.8EG 9.82023-11-29
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the authorization header used for user login remaining valid an…
- CVE-2023-5865CRITICALCVSS 9.8EG 9.82023-10-31
Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
- CVE-2023-5838CRITICALCVSS 9.8EG 9.82023-10-29
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.
- CVE-2023-46158CRITICALCVSS 9.8EG 9.82023-10-25
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
- CVE-2023-4005CRITICALCVSS 9.8EG 9.82023-07-31
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
- CVE-2023-35857CRITICALCVSS 9.8EG 9.82023-06-19
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
- CVE-2023-1788CRITICALCVSS 9.8EG 9.82023-04-05
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
- CVE-2022-36179CRITICALCVSS 9.8EG 9.82022-11-22
Fusiondirectory 1.3 suffers from Improper Session Handling.
- CVE-2022-4070CRITICALCVSS 9.8EG 9.82022-11-20
Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.
- CVE-2022-3362CRITICALCVSS 9.8EG 9.82022-11-14
Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
- CVE-2022-2713CRITICALCVSS 9.8EG 9.82022-08-08
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
- CVE-2022-22318CRITICALCVSS 9.8EG 9.82022-06-20
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
- CVE-2022-22317CRITICALCVSS 9.8EG 9.82022-06-20
IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.
- CVE-2021-25992CRITICALCVSS 9.8EG 9.82022-02-10
In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetic…
- CVE-2021-22820CRITICALCVSS 9.8EG 9.82022-01-28
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has chan…
- CVE-2021-25981CRITICALCVSS 9.8EG 9.82022-01-03
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even…
- CVE-2020-27416CRITICALCVSS 9.8EG 9.82021-12-08
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.
- CVE-2021-25979CRITICALCVSS 9.8EG 9.82021-11-08
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those …
- CVE-2021-40849CRITICALCVSS 9.8EG 9.82021-11-03
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileg…
- CVE-2021-38823CRITICALCVSS 9.8EG 9.82021-10-04
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
- CVE-2021-37333CRITICALCVSS 9.8EG 9.82021-10-04
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.
- CVE-2020-35358CRITICALCVSS 9.8EG 9.82021-03-15
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. …
- CVE-2020-6649CRITICALCVSS 9.8EG 9.82021-02-08
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that s…
- CVE-2021-3311CRITICALCVSS 9.8EG 9.82021-02-05
An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the intended Auth/Manager.php authentication behavior but, admitted…
- CVE-2020-29667CRITICALCVSS 9.8EG 9.82020-12-10
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →