CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 1 of 7
- CVE-2023-7028CRITICALCVSS 10.0EG 10.0⚠ KEV2024-01-12
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which …
- CVE-2025-4320CRITICALCVSS 10.0EG 10.02026-01-23
Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation. This …
- CVE-2025-63314CRITICALCVSS 10.0EG 10.02026-01-12
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.
- CVE-2026-102115CRITICALCVSS 9.8EG 9.82026-09-30
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password…
- CVE-2026-71625CRITICALCVSS 9.8EG 9.82026-09-04
An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component
- CVE-2026-19632CRITICALCVSS 9.8EG 9.82026-08-26
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. Th…
- CVE-2026-77264CRITICALCVSS 9.8EG 9.82026-08-21
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() …
- CVE-2026-15689CRITICALCVSS 9.8EG 9.82026-08-15
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$ba…
- CVE-2026-12949CRITICALCVSS 9.8EG 9.82026-08-14
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration co…
- CVE-2026-66691CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
- CVE-2026-61967CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
- CVE-2026-12571CRITICALCVSS 9.8EG 9.82026-08-11
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
- CVE-2026-14364CRITICALCVSS 9.8EG 9.82026-08-07
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly v…
- CVE-2026-13019CRITICALCVSS 9.8EG 9.82026-07-07
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versi…
- CVE-2026-13020CRITICALCVSS 9.8EG 9.82026-07-07
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulati…
- CVE-2026-37106CRITICALCVSS 9.8EG 9.82026-06-30
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is …
- CVE-2026-12417CRITICALCVSS 9.8EG 9.82026-06-24
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX hand…
- CVE-2026-12416CRITICALCVSS 9.8EG 9.82026-06-24
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX h…
- CVE-2026-11551CRITICALCVSS 9.8EG 9.82026-06-20
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. …
- CVE-2026-32865CRITICALCVSS 9.8EG 9.82026-03-19
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset …
- CVE-2026-28268CRITICALCVSS 9.8EG 9.82026-02-27
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. …
- CVE-2026-28213CRITICALCVSS 9.8EG 9.82026-02-26
EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows …
- CVE-2026-26273CRITICALCVSS 9.8EG 9.82026-02-13
Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset …
- CVE-2020-37172CRITICALCVSS 9.8EG 9.82026-02-11
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using t…
- CVE-2026-25858CRITICALCVSS 9.8EG 9.82026-02-07
macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone…
- CVE-2026-1325CRITICALCVSS 9.8EG 9.82026-01-22
A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results …
- CVE-2022-50910CRITICALCVSS 9.8EG 9.82026-01-13
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset t…
- CVE-2025-64113CRITICALCVSS 9.8EG 9.82025-12-09
Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specif…
- CVE-2025-50433CRITICALCVSS 9.8EG 9.82025-11-26
An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.
- CVE-2025-12866CRITICALCVSS 9.8EG 9.82025-11-10
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
- CVE-2025-10127CRITICALCVSS 9.8EG 9.82025-09-11
Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without pri…
- CVE-2025-32486CRITICALCVSS 9.8EG 9.82025-09-09
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.
- CVE-2025-50594CRITICALCVSS 9.8EG 9.82025-08-13
An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password.
- CVE-2025-43932CRITICALCVSS 9.8EG 9.82025-07-07
JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
- CVE-2025-43931CRITICALCVSS 9.8EG 9.82025-07-07
flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.
- CVE-2025-6216CRITICALCVSS 9.8EG 9.82025-06-21
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this v…
- CVE-2025-6097CRITICALCVSS 9.8EG 9.82025-06-16
A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the file /goform/setSysAdm of the component Administrator Password Handler. The manipulation …
- CVE-2025-47646CRITICALCVSS 9.8EG 9.82025-05-23
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Regi…
- CVE-2025-31380CRITICALCVSS 9.8EG 9.82025-04-17
Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.…
- CVE-2025-22144CRITICALCVSS 9.8EG 9.82025-01-13
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is success…
- CVE-2024-11350CRITICALCVSS 9.8EG 9.82025-01-08
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password t…
- CVE-2024-53552CRITICALCVSS 9.8EG 9.82024-12-10
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
- CVE-2024-11103CRITICALCVSS 9.8EG 9.82024-11-28
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their p…
- CVE-2024-48428CRITICALCVSS 9.8EG 9.82024-10-25
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
- CVE-2024-8878CRITICALCVSS 9.8EG 9.82024-09-25
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
- CVE-2024-38287CRITICALCVSS 9.8EG 9.82024-07-25
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit v…
- CVE-2024-38468CRITICALCVSS 9.8EG 9.82024-06-16
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
- CVE-2024-5404CRITICALCVSS 9.8EG 9.82024-06-03
An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.
- CVE-2023-4214CRITICALCVSS 9.8EG 9.82023-11-18
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or…
- CVE-2023-43902CRITICALCVSS 9.8EG 9.82023-11-14
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password rese…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →