CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 2 of 7
- CVE-2023-4448CRITICALCVSS 9.8EG 9.82023-08-21
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password rec…
- CVE-2023-36487CRITICALCVSS 9.8EG 9.82023-06-29
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
- CVE-2023-30466CRITICALCVSS 9.8EG 9.82023-04-28
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remo…
- CVE-2022-45637CRITICALCVSS 9.8EG 9.82023-03-21
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
- CVE-2022-47697CRITICALCVSS 9.8EG 9.82023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.
- CVE-2022-47377CRITICALCVSS 9.8EG 9.82022-12-16
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery m…
- CVE-2022-3485CRITICALCVSS 9.8EG 9.82022-12-12
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
- CVE-2022-44004CRITICALCVSS 9.8EG 9.82022-11-16
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
- CVE-2022-37300CRITICALCVSS 9.8EG 9.82022-09-12
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Ex…
- CVE-2022-27157CRITICALCVSS 9.8EG 9.82022-04-15
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
- CVE-2022-23855CRITICALCVSS 9.8EG 9.82022-01-24
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.
- CVE-2021-41694CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
- CVE-2021-36209CRITICALCVSS 9.8EG 9.82021-08-06
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
- CVE-2021-22763CRITICALCVSS 9.8EG 9.82021-06-11
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow a…
- CVE-2021-28293CRITICALCVSS 9.8EG 9.82021-06-08
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password …
- CVE-2021-22731CRITICALCVSS 9.8EG 9.82021-05-26
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information i…
- CVE-2020-27179CRITICALCVSS 9.8EG 9.82020-10-27
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
- CVE-2020-25105CRITICALCVSS 9.8EG 9.82020-09-03
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
- CVE-2012-5686CRITICALCVSS 9.8EG 9.82020-02-04
ZPanel 10.0.1 has insufficient entropy for its password reset process.
- CVE-2012-5618CRITICALCVSS 9.8EG 9.82020-02-04
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
- CVE-2020-7245CRITICALCVSS 9.8EG 9.82020-01-23
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one …
- CVE-2019-19844CRITICALCVSS 9.8EG 9.82019-12-18
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an atta…
- CVE-2019-17392CRITICALCVSS 9.8EG 9.82019-11-26
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
- CVE-2019-18818CRITICALCVSS 9.8EG 9.82019-11-07
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
- CVE-2019-15929CRITICALCVSS 9.8EG 9.82019-10-24
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
- CVE-2018-16988CRITICALCVSS 9.8EG 9.82019-05-02
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situat…
- CVE-2019-11393CRITICALCVSS 9.8EG 9.82019-04-22
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
- CVE-2019-10641CRITICALCVSS 9.8EG 9.82019-04-17
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
- CVE-2018-16529CRITICALCVSS 9.8EG 9.82019-03-28
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.
- CVE-2018-19488CRITICALCVSS 9.8EG 9.82019-03-21
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's acc…
- CVE-2018-18871CRITICALCVSS 9.8EG 9.82018-12-20
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without…
- CVE-2018-7811CRITICALCVSS 9.8EG 9.82018-11-30
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web ser…
- CVE-2018-7809CRITICALCVSS 9.8EG 9.82018-11-30
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web ser…
- CVE-2018-17881CRITICALCVSS 9.8EG 9.82018-10-03
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.
- CVE-2018-17298CRITICALCVSS 9.8EG 9.82018-09-21
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
- CVE-2018-1000554CRITICALCVSS 9.8EG 9.82018-06-26
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have be…
- CVE-2018-1000501CRITICALCVSS 9.8EG 9.82018-06-26
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulner…
- CVE-2018-12421CRITICALCVSS 9.8EG 9.82018-06-14
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constr…
- CVE-2018-10081CRITICALCVSS 9.8EG 9.82018-04-13
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.
- CVE-2017-17097CRITICALCVSS 9.8EG 9.82018-01-02
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which mak…
- CVE-2015-5172CRITICALCVSS 9.8EG 9.82017-10-24
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
- CVE-2015-4689CRITICALCVSS 9.8EG 9.82017-09-11
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
- CVE-2017-7551CRITICALCVSS 9.8EG 9.82017-08-16
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
- CVE-2017-2766CRITICALCVSS 9.8EG 9.82017-02-03
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could po…
- CVE-2022-45782CRITICALCVSS 8.8EG 9.82023-02-01
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.
- CVE-2022-1073CRITICALCVSS 7.3EG 9.82022-03-29
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
- CVE-2026-53595CRITICALCVSS 9.4EG 9.42026-07-20
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely …
- CVE-2026-33707CRITICALCVSS 9.4EG 9.42026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a u…
- CVE-2025-69614CRITICALCVSS 9.4EG 9.42026-03-10
Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 20…
- CVE-2025-4319CRITICALCVSS 9.4EG 9.42026-01-23
Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation. …
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →