CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
321 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 2 of 7
- CVE-2018-19488CRITICALCVSS 9.8EG 9.82019-03-21
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's acc…
- CVE-2018-7809CRITICALCVSS 9.8EG 9.82018-11-30
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web ser…
- CVE-2018-7811CRITICALCVSS 9.8EG 9.82018-11-30
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web ser…
- CVE-2018-8916HIGHCVSS 6.3EG 8.82018-06-08
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
- CVE-2019-10270HIGHCVSS 8.8EG 8.82019-06-21
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset …
- CVE-2019-10641CRITICALCVSS 9.8EG 9.82019-04-17
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
- CVE-2019-11393CRITICALCVSS 9.8EG 9.82019-04-22
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
- CVE-2019-11414HIGHCVSS 8.8EG 8.82019-04-22
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete…
- CVE-2019-12476MEDIUMCVSS 6.8EG 6.82019-06-17
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client …
- CVE-2019-12943HIGHCVSS 8.1EG 8.12019-09-10
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names.
- CVE-2019-13240MEDIUMCVSS 5.9EG 5.92019-07-10
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
- CVE-2019-14955MEDIUMCVSS 5.3EG 5.32019-10-01
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
- CVE-2019-15749MEDIUMCVSS 6.5EG 6.52019-10-07
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS …
- CVE-2019-15929CRITICALCVSS 9.8EG 9.82019-10-24
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
- CVE-2019-17392CRITICALCVSS 9.8EG 9.82019-11-26
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
- CVE-2019-18818CRITICALCVSS 9.8EG 9.82019-11-07
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
- CVE-2019-19844CRITICALCVSS 9.8EG 9.82019-12-18
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an atta…
- CVE-2019-20004HIGHCVSS 8.8EG 8.82020-01-05
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete…
- CVE-2019-3787HIGHCVSS 8.3EG 8.32019-06-19
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which le…
- CVE-2019-6560CRITICALCVSS 9.1EG 9.12020-03-23
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but…
- CVE-2020-11027MEDIUMCVSS 6.1EG 6.12020-04-30
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has bee…
- CVE-2020-12067HIGHCVSS 7.5EG 7.52022-12-26
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
- CVE-2020-14015HIGHCVSS 7.5EG 7.52020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system w…
- CVE-2020-14016MEDIUMCVSS 5.3EG 5.32020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature returns a not_foun…
- CVE-2020-15949HIGHCVSS 7.5EG 7.52020-11-05
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
- CVE-2020-25105CRITICALCVSS 9.8EG 9.82020-09-03
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
- CVE-2020-25728HIGHCVSS 8.8EG 8.82020-09-17
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
- CVE-2020-26061HIGHCVSS 7.5EG 7.52020-10-05
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questio…
- CVE-2020-27179CRITICALCVSS 9.8EG 9.82020-10-27
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
- CVE-2020-27408HIGHCVSS 7.5EG 7.52020-12-04
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
- CVE-2020-28186HIGHCVSS 7.3EG 7.32020-12-24
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
- CVE-2020-37158HIGHCVSS 8.8EG 8.82026-02-11
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using t…
- CVE-2020-37172CRITICALCVSS 9.8EG 9.82026-02-11
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using t…
- CVE-2020-5361MEDIUMCVSS 5.1EG 5.12021-01-04
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can gene…
- CVE-2020-5899HIGHCVSS 7.8EG 7.82020-07-01
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the data…
- CVE-2020-7245CRITICALCVSS 9.8EG 9.82020-01-23
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one …
- CVE-2021-22731CRITICALCVSS 9.8EG 9.82021-05-26
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information i…
- CVE-2021-22763CRITICALCVSS 9.8EG 9.82021-06-11
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow a…
- CVE-2021-25323CRITICALCVSS 9.1EG 9.12021-01-19
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
- CVE-2021-25957HIGHCVSS 8.8EG 8.82021-08-17
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user re…
- CVE-2021-25961HIGHCVSS 8.0EG 8.02021-09-29
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly cr…
- CVE-2021-27654HIGHCVSS 7.8EG 7.82022-01-28
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
- CVE-2021-28128HIGHCVSS 8.1EG 8.12021-05-06
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.
- CVE-2021-28293CRITICALCVSS 9.8EG 9.82021-06-08
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password …
- CVE-2021-29038MEDIUMCVSS 6.3EG 6.32024-02-20
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attack…
- CVE-2021-29080HIGHCVSS 8.1EG 8.12021-03-23
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2…
- CVE-2021-31912HIGHCVSS 8.8EG 8.82021-05-11
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
- CVE-2021-33321HIGHCVSS 7.5EG 7.52021-08-03
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.passwo…
- CVE-2021-36095MEDIUMCVSS 5.3EG 5.32021-09-06
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
- CVE-2021-36209CRITICALCVSS 9.8EG 9.82021-08-06
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →