CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
664 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 3 of 14
- CVE-2025-66289HIGHCVSS 8.8EG 8.82025-11-29
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies t…
- CVE-2025-40566HIGHCVSS 8.8EG 8.82025-05-13
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow…
- CVE-2025-24859HIGHCVSS 8.8EG 8.82025-04-14
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an admin…
- CVE-2024-45386HIGHCVSS 8.8EG 8.82025-02-11
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Saf…
- CVE-2024-52553HIGHCVSS 8.8EG 8.82024-11-13
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
- CVE-2024-48827HIGHCVSS 8.8EG 8.82024-10-11
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.
- CVE-2024-5995HIGHCVSS 8.8EG 8.82024-06-14
The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.
- CVE-2024-4680HIGHCVSS 8.8EG 8.82024-06-08
A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expiration. Specifically, the session does not expire after a password change, enabling an attack…
- CVE-2024-35050HIGHCVSS 8.8EG 8.82024-05-14
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
- CVE-2024-34092HIGHCVSS 8.8EG 8.82024-05-06
An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release.
- CVE-2023-51772HIGHCVSS 8.8EG 8.82023-12-25
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide th…
- CVE-2023-49935HIGHCVSS 8.8EG 8.82023-12-14
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with the slurmd process…
- CVE-2023-46326HIGHCVSS 8.8EG 8.82023-11-30
ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation.
- CVE-2023-4126HIGHCVSS 8.8EG 8.82023-08-03
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
- CVE-2023-36252HIGHCVSS 8.8EG 8.82023-06-26
An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.
- CVE-2023-1543HIGHCVSS 8.8EG 8.82023-03-21
Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-23929HIGHCVSS 8.8EG 8.82023-03-04
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0…
- CVE-2023-24426HIGHCVSS 8.8EG 8.82023-01-26
Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.
- CVE-2023-23614HIGHCVSS 8.8EG 8.82023-01-26
Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Rem…
- CVE-2022-43844HIGHCVSS 8.8EG 8.82023-01-05
IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 2390…
- CVE-2022-2064HIGHCVSS 8.8EG 8.82022-06-13
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
- CVE-2022-23669HIGHCVSS 8.8EG 8.82022-05-17
A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that a…
- CVE-2022-23063HIGHCVSS 8.8EG 8.82022-05-03
In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even a…
- CVE-2022-22113HIGHCVSS 8.8EG 8.82022-01-13
In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the…
- CVE-2021-25940HIGHCVSS 8.8EG 8.82021-11-16
In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and p…
- CVE-2021-25970HIGHCVSS 8.8EG 8.82021-10-20
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was c…
- CVE-2021-25966HIGHCVSS 8.8EG 8.82021-10-10
In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already…
- CVE-2021-20378HIGHCVSS 8.8EG 8.82021-07-07
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 195709.
- CVE-2020-15950HIGHCVSS 8.8EG 8.82020-11-05
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
- CVE-2020-6292HIGHCVSS 8.8EG 8.82020-07-14
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.
- CVE-2020-6291HIGHCVSS 8.8EG 8.82020-07-14
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration
- CVE-2020-12690HIGHCVSS 8.8EG 8.82020-05-07
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains…
- CVE-2020-4253HIGHCVSS 8.8EG 8.82020-03-24
IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.
- CVE-2019-5462HIGHCVSS 8.8EG 8.82020-01-28
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.
- CVE-2019-10229HIGHCVSS 8.8EG 8.82019-12-31
An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) is set to Generic LDAP, an attacker is able to login as an e…
- CVE-2019-12421HIGHCVSS 8.8EG 8.82019-11-19
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-si…
- CVE-2019-17375HIGHCVSS 8.8EG 8.82019-10-09
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
- CVE-2019-7280HIGHCVSS 8.8EG 8.82019-07-01
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.
- CVE-2019-6584HIGHCVSS 8.8EG 8.82019-06-12
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated webserver does not …
- CVE-2018-0152HIGHCVSS 8.8EG 8.82018-03-28
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does …
- CVE-2018-1195HIGHCVSS 8.8EG 8.82018-03-19
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerab…
- CVE-2017-15653HIGHCVSS 8.8EG 8.82018-01-31
Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specifi…
- CVE-2017-6529HIGHCVSS 8.8EG 8.82017-03-09
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter.
- CVE-2023-33005HIGHCVSS 5.4EG 8.82023-05-16
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
- CVE-2026-88262HIGHCVSS 8.7EG 8.72026-09-15
Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.
- CVE-2026-55250HIGHCVSS 8.7EG 8.72026-09-08
Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perfor…
- CVE-2026-43918HIGHCVSS 8.7EG 8.72026-07-06
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identit…
- CVE-2025-49152HIGHCVSS 8.7EG 8.72025-06-25
The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.
- CVE-2019-5638HIGHCVSS 8.7EG 8.72019-08-21
Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator d…
- CVE-2026-27764HIGHCVSS 8.6EG 8.62026-03-06
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables s…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →