CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
664 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 6 of 14
- CVE-2020-11795HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- CVE-2020-11688HIGHCVSS 7.5EG 7.52020-04-22
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- CVE-2018-14345HIGHCVSS 7.5EG 7.52018-07-17
An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for users with an already existing session. Any user with access to the system D-Bus can therefore unlock any graphical sessi…
- CVE-2017-12159HIGHCVSS 7.5EG 7.52017-10-26
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attack…
- CVE-2022-0996HIGHCVSS 6.5EG 7.52022-03-23
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
- CVE-2026-79664HIGHCVSS 7.4EG 7.42026-08-25
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on nil …
- CVE-2026-48079HIGHCVSS 7.4EG 7.42026-08-06
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token`…
- CVE-2026-51953HIGHCVSS 7.4EG 7.42026-07-31
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components
- CVE-2026-64829HIGHCVSS 7.4EG 7.42026-07-22
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear …
- CVE-2026-44511HIGHCVSS 7.4EG 7.42026-05-14
Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue…
- CVE-2026-32132HIGHCVSS 7.4EG 7.42026-03-11
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved co…
- CVE-2024-33507HIGHCVSS 7.4EG 7.42025-10-14
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism ma…
- CVE-2024-41827HIGHCVSS 7.4EG 7.42024-07-22
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
- CVE-2024-35220HIGHCVSS 7.4EG 7.42024-05-21
@fastify/session is a session plugin for fastify. Requires the @fastify/cookie plugin. When restoring the cookie from the session store, the `expires` field is overriden if the `maxAge` field was set. This means a cookie is never correctly…
- CVE-2024-31999HIGHCVSS 7.4EG 7.42024-04-10
@festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it will encrypt all data in the session with a secret key and attach the ciphertext as a cookie value with the defined cooki…
- CVE-2021-35034HIGHCVSS 7.4EG 7.42021-12-29
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
- CVE-2021-41100HIGHCVSS 7.4EG 7.42021-10-04
Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only the short-lived session token in the `Authorization` header. A…
- CVE-2021-32923HIGHCVSS 7.4EG 7.42021-06-03
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring durin…
- CVE-2020-15269HIGHCVSS 7.4EG 7.42020-10-20
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is described in the linke…
- CVE-2019-19199HIGHCVSS 7.4EG 7.42020-10-02
REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.
- CVE-2017-12191HIGHCVSS 7.4EG 7.42018-02-28
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and …
- CVE-2026-97212HIGHCVSS 7.3EG 7.32026-10-02
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnera…
- CVE-2026-54479HIGHCVSS 7.3EG 7.32026-06-25
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnera…
- CVE-2025-22386HIGHCVSS 7.3EG 7.32025-01-04
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tie…
- CVE-2023-38489HIGHCVSS 7.3EG 7.32023-07-27
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be a…
- CVE-2019-9269HIGHCVSS 7.3EG 7.32019-09-27
In System Settings, there is a possible permissions bypass due to a cached Linux user ID. This could lead to a local permissions bypass with no additional execution privileges needed. User interaction is needed for exploitation. Product: A…
- CVE-2017-6145HIGHCVSS 7.3EG 7.32017-10-20
iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This serv…
- CVE-2026-32663HIGHCVSS 6.5EG 7.32026-03-20
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables s…
- CVE-2026-27649HIGHCVSS 6.5EG 7.32026-03-20
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables …
- CVE-2026-82310HIGHCVSS 7.2EG 7.22026-09-16
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, une…
- CVE-2024-22389HIGHCVSS 7.2EG 7.22024-02-14
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2023-42768HIGHCVSS 7.2EG 7.22023-10-10
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can…
- CVE-2023-37570HIGHCVSS 7.2EG 7.22023-08-08
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
- CVE-2023-32318HIGHCVSS 7.2EG 7.22023-05-26
Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After succes…
- CVE-2026-85387HIGHCVSS 7.1EG 7.12026-09-16
Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a tok…
- CVE-2026-63175HIGHCVSS 7.1EG 7.12026-07-15
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state…
- CVE-2026-59219HIGHCVSS 7.1EG 7.12026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authenti…
- CVE-2026-46657HIGHCVSS 7.1EG 7.12026-06-08
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a us…
- CVE-2026-34828HIGHCVSS 7.1EG 7.12026-04-02
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive acco…
- CVE-2026-33417HIGHCVSS 7.1EG 7.12026-03-24
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the token validation logic n…
- CVE-2025-15553HIGHCVSS 7.1EG 7.12026-03-16
Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
- CVE-2025-11699HIGHCVSS 7.1EG 7.12025-12-01
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after th…
- CVE-2025-59335HIGHCVSS 7.1EG 7.12025-09-22
CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a locat…
- CVE-2025-50486HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.
- CVE-2025-50485HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.
- CVE-2025-50487HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.
- CVE-2025-50484HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
- CVE-2025-50491HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.
- CVE-2025-50488HIGHCVSS 7.1EG 7.12025-07-28
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.
- CVE-2025-31952HIGHCVSS 7.1EG 7.12025-07-24
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →