CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 3 of 7
- CVE-2024-47547CRITICALCVSS 9.4EG 9.42024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.
- CVE-2026-9273CRITICALCVSS 9.3EG 9.32026-08-05
The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legac…
- CVE-2026-107640CRITICALCVSS 9.1EG 9.12026-10-08
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target …
- CVE-2026-19218CRITICALCVSS 9.1EG 9.12026-10-08
Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation. This issue affects MyRezzta: from 2.06.03 before 2.0…
- CVE-2026-53953CRITICALCVSS 9.1EG 9.12026-10-01
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an …
- CVE-2026-84699CRITICALCVSS 9.1EG 9.12026-09-02
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized…
- CVE-2026-18963CRITICALCVSS 9.1EG 9.12026-08-18
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password…
- CVE-2026-18363CRITICALCVSS 9.1EG 9.12026-07-30
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided …
- CVE-2026-56081CRITICALCVSS 9.1EG 9.12026-06-19
Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered…
- CVE-2026-34408CRITICALCVSS 9.1EG 9.12026-05-05
An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.
- CVE-2026-34751CRITICALCVSS 9.1EG 9.12026-04-01
Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on b…
- CVE-2025-13565CRITICALCVSS 9.1EG 9.12025-11-23
A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack …
- CVE-2024-2862CRITICALCVSS 9.1EG 9.12024-03-25
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
- CVE-2023-0352CRITICALCVSS 9.1EG 9.12023-03-13
The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.
- CVE-2021-25323CRITICALCVSS 9.1EG 9.12021-01-19
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
- CVE-2019-6560CRITICALCVSS 9.1EG 9.12020-03-23
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but…
- CVE-2026-24467CRITICALCVSS 9.0EG 9.02026-04-20
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's password reset implementation contains …
- CVE-2017-7615CRITICALCVSS 8.8EG 9.02017-04-16
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
- CVE-2025-53373HIGHCVSS 8.9EG 8.92025-07-07
Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server domain in the Host header when requesting the /forgetpassword endpoint. This vulnerability is fixed with commit …
- CVE-2026-100870HIGHCVSS 8.8EG 8.82026-09-27
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controll…
- CVE-2026-14850HIGHCVSS 8.8EG 8.82026-09-17
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users w…
- CVE-2026-72772HIGHCVSS 8.8EG 8.82026-08-11
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the…
- CVE-2026-15155HIGHCVSS 8.8EG 8.82026-07-11
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insuff…
- CVE-2026-55207HIGHCVSS 8.8EG 8.82026-07-09
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with …
- CVE-2026-50635HIGHCVSS 8.8EG 8.82026-06-09
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, s…
- CVE-2026-42606HIGHCVSS 8.8EG 8.82026-05-09
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthen…
- CVE-2026-27593HIGHCVSS 8.8EG 8.82026-02-24
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their b…
- CVE-2020-37158HIGHCVSS 8.8EG 8.82026-02-11
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using t…
- CVE-2024-32642HIGHCVSS 8.8EG 8.82025-12-03
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8…
- CVE-2025-66225HIGHCVSS 8.8EG 8.82025-11-29
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset proce…
- CVE-2025-62709HIGHCVSS 8.8EG 8.82025-11-20
ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from the incoming HTTP Host header when the configuration base_ur…
- CVE-2025-62406HIGHCVSS 8.8EG 8.82025-11-18
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset URL by entering an existing username or email address. However, the hostname u…
- CVE-2025-64101HIGHCVSS 8.8EG 8.82025-10-29
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming re…
- CVE-2025-50503HIGHCVSS 8.8EG 8.82025-08-20
A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password …
- CVE-2024-12295HIGHCVSS 8.8EG 8.82025-03-19
The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating…
- CVE-2024-45980HIGHCVSS 8.8EG 8.82024-09-26
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compr…
- CVE-2023-35717HIGHCVSS 8.8EG 8.82024-05-03
TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link Tapo C210 IP cameras. Authentication is not require…
- CVE-2024-27899HIGHCVSS 8.8EG 8.82024-04-09
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause…
- CVE-2024-22454HIGHCVSS 8.8EG 8.82024-02-13
Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized …
- CVE-2023-49589HIGHCVSS 8.8EG 8.82024-01-10
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An …
- CVE-2023-49097HIGHCVSS 8.8EG 8.82023-11-30
ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this hea…
- CVE-2023-47107HIGHCVSS 8.8EG 8.82023-11-08
PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It …
- CVE-2023-5840HIGHCVSS 8.8EG 8.82023-10-29
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
- CVE-2023-31459HIGHCVSS 8.8EG 8.82023-05-24
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, becaus…
- CVE-2022-29933HIGHCVSS 8.8EG 8.82022-05-09
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the passw…
- CVE-2021-25957HIGHCVSS 8.8EG 8.82021-08-17
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user re…
- CVE-2021-31912HIGHCVSS 8.8EG 8.82021-05-11
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
- CVE-2020-25728HIGHCVSS 8.8EG 8.82020-09-17
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
- CVE-2019-20004HIGHCVSS 8.8EG 8.82020-01-05
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete…
- CVE-2019-10270HIGHCVSS 8.8EG 8.82019-06-21
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset …
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →