CWE-620— Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.— MITRE CWE catalog
101 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-620page 1 of 3
- CVE-2024-20419CRITICALCVSS 10.0EG 10.02024-07-17
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is…
- CVE-2025-1107CRITICALCVSS 9.9EG 9.92025-02-07
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker mus…
- CVE-2024-33699CRITICALCVSS 9.9EG 9.92024-10-30
The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.
- CVE-2026-15964CRITICALCVSS 9.8EG 9.82026-08-01
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_aj…
- CVE-2026-12692CRITICALCVSS 9.8EG 9.82026-07-17
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
- CVE-2025-70082CRITICALCVSS 9.8EG 9.82026-03-11
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
- CVE-2025-67041CRITICALCVSS 9.8EG 9.82026-03-11
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary on…
- CVE-2025-63362CRITICALCVSS 9.8EG 9.82025-12-04
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to set the Administrator password and username as blank values, allowing attackers to bypass…
- CVE-2025-9286CRITICALCVSS 9.8EG 9.82025-10-03
The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible …
- CVE-2025-10159CRITICALCVSS 9.8EG 9.82025-09-09
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
- CVE-2025-4606CRITICALCVSS 9.8EG 9.82025-07-09
The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.4. This is due to the theme not properly validating a user's identity prior …
- CVE-2024-12827CRITICALCVSS 9.8EG 9.82025-06-27
The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.6. This is due to the plugin not properly checking for an empty token va…
- CVE-2025-6097CRITICALCVSS 9.8EG 9.82025-06-16
A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the file /goform/setSysAdm of the component Administrator Password Handler. The manipulation …
- CVE-2025-4322CRITICALCVSS 9.8EG 9.82025-05-20
The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. Th…
- CVE-2025-4558CRITICALCVSS 9.8EG 9.82025-05-12
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
- CVE-2025-2253CRITICALCVSS 9.8EG 9.82025-05-09
The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password…
- CVE-2025-3603CRITICALCVSS 9.8EG 9.82025-04-24
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their deta…
- CVE-2024-48887CRITICALCVSS 9.8EG 9.82025-04-08
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request
- CVE-2024-12824CRITICALCVSS 9.8EG 9.82025-03-01
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value pr…
- CVE-2024-12860CRITICALCVSS 9.8EG 9.82025-02-18
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token pri…
- CVE-2024-13375CRITICALCVSS 9.8EG 9.82025-01-18
The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their det…
- CVE-2024-26520CRITICALCVSS 9.8EG 9.82024-07-26
An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.
- CVE-2024-37998CRITICALCVSS 9.8EG 9.82024-07-22
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without re…
- CVE-2023-2449CRITICALCVSS 9.8EG 9.82023-11-22
The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset …
- CVE-2023-4214CRITICALCVSS 9.8EG 9.82023-11-18
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or…
- CVE-2023-3069CRITICALCVSS 9.8EG 9.82023-06-02
Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
- CVE-2023-2297CRITICALCVSS 9.8EG 9.82023-04-27
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality,…
- CVE-2026-77644CRITICALCVSS 9.3EG 9.32026-08-20
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
- CVE-2026-91995CRITICALCVSS 9.1EG 9.12026-09-15
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with …
- CVE-2026-5386CRITICALCVSS 9.1EG 9.12026-05-29
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access t…
- CVE-2026-30458CRITICALCVSS 9.1EG 9.12026-03-26
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
- CVE-2020-7378CRITICALCVSS 9.1EG 9.12020-11-24
CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standa…
- CVE-2025-71328HIGHCVSS 8.8EG 8.82026-06-25
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional ve…
- CVE-2026-24443HIGHCVSS 8.8EG 8.82026-02-24
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current pass…
- CVE-2026-24440HIGHCVSS 8.8EG 8.82026-01-26
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized passw…
- CVE-2025-5482HIGHCVSS 8.8EG 8.82025-06-04
The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly val…
- CVE-2025-3607HIGHCVSS 8.8EG 8.82025-04-24
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity pri…
- CVE-2024-9431HIGHCVSS 8.8EG 8.82025-03-20
In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.
- CVE-2022-3152HIGHCVSS 8.8EG 8.82022-09-07
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
- CVE-2017-14005HIGHCVSS 8.8EG 8.82017-10-17
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is au…
- CVE-2022-21934HIGHCVSS 8.0EG 8.82022-05-06
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.
- CVE-2018-8916HIGHCVSS 6.3EG 8.82018-06-08
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
- CVE-2025-14751HIGHCVSS 8.7EG 8.72026-01-22
A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.
- CVE-2025-67719HIGHCVSS 8.5EG 8.52025-12-11
Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the valid…
- CVE-2024-28143HIGHCVSS 8.4EG 8.42024-12-12
The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+-…
- CVE-2026-92467HIGHCVSS 8.3EG 8.32026-09-16
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. At…
- CVE-2026-73292HIGHCVSS 8.3EG 8.32026-08-12
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pass…
- CVE-2026-56305HIGHCVSS 8.3EG 8.32026-07-10
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access c…
- CVE-2025-71337HIGHCVSS 8.3EG 8.32026-06-23
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the ac…
- CVE-2025-62425HIGHCVSS 8.3EG 8.32025-10-16
MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with acces…
Map vulnerabilities like CWE-620 to your infrastructure
EchelonGraph correlates every CVE — across CWE-620 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →