CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 4 of 7
- CVE-2019-11414HIGHCVSS 8.8EG 8.82019-04-22
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete…
- CVE-2018-17401HIGHCVSS 8.8EG 8.82018-09-23
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the us…
- CVE-2018-11134HIGHCVSS 8.8EG 8.82018-05-31
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available comman…
- CVE-2018-0787HIGHCVSS 8.8EG 8.82018-03-14
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
- CVE-2017-12161HIGHCVSS 8.8EG 8.82018-02-21
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid re…
- CVE-2017-14005HIGHCVSS 8.8EG 8.82017-10-17
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is au…
- CVE-2017-12851HIGHCVSS 8.8EG 8.82017-08-14
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
- CVE-2017-12850HIGHCVSS 8.8EG 8.82017-08-14
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.
- CVE-2022-26872HIGHCVSS 8.3EG 8.82023-01-30
AMI Megarac Password reset interception via API
- CVE-2018-8916HIGHCVSS 6.3EG 8.82018-06-08
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
- CVE-2023-4096HIGHCVSS 8.2EG 8.62023-09-19
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate…
- CVE-2026-101188HIGHCVSS 8.3EG 8.32026-09-28
A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remo…
- CVE-2026-93453HIGHCVSS 8.3EG 8.32026-09-17
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password reco…
- CVE-2025-29995HIGHCVSS 8.3EG 8.32025-03-13
This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable AP…
- CVE-2024-6203HIGHCVSS 8.3EG 8.32024-08-06
HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.…
- CVE-2019-3787HIGHCVSS 8.3EG 8.32019-06-19
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which le…
- CVE-2026-35676HIGHCVSS 8.2EG 8.22026-05-20
phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and …
- CVE-2026-72856HIGHCVSS 8.1EG 8.12026-08-13
Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRest…
- CVE-2026-7655HIGHCVSS 8.1EG 8.12026-07-11
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like …
- CVE-2026-45013HIGHCVSS 8.1EG 8.12026-05-14
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HT…
- CVE-2026-29199HIGHCVSS 8.1EG 8.12026-05-04
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the pas…
- CVE-2026-28681HIGHCVSS 8.1EG 8.12026-03-06
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP…
- CVE-2026-2895HIGHCVSS 8.1EG 8.12026-02-21
A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak pa…
- CVE-2026-2564HIGHCVSS 8.1EG 8.12026-02-16
A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to lau…
- CVE-2025-15398HIGHCVSS 8.1EG 8.12025-12-31
A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password …
- CVE-2025-8855HIGHCVSS 8.1EG 8.12025-11-14
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Cl…
- CVE-2025-41251HIGHCVSS 8.1EG 8.12025-09-29
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential…
- CVE-2025-52560HIGHCVSS 8.1EG 8.12025-06-24
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with URLs derived from the unvalidated Host header when the application_url configura…
- CVE-2025-1570HIGHCVSS 8.1EG 8.12025-02-28
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_ge…
- CVE-2024-9302HIGHCVSS 8.1EG 8.12024-10-25
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password()…
- CVE-2024-9305HIGHCVSS 8.1EG 8.12024-10-16
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() fun…
- CVE-2024-6125HIGHCVSS 8.1EG 8.12024-06-19
The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.7.34. This is due to the plugin generating too weak a reset code, and the code used to reset the password has…
- CVE-2023-7264HIGHCVSS 8.1EG 8.12024-06-11
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of …
- CVE-2024-0186HIGHCVSS 8.1EG 8.12024-01-02
A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unknown function of the file /user/index/findpass?do=4 of the component HTTP POST Request Handler. The manipulation leads t…
- CVE-2023-42481HIGHCVSS 8.1EG 8.12023-12-12
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP…
- CVE-2022-29174HIGHCVSS 8.1EG 8.12022-05-17
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of gue…
- CVE-2021-28128HIGHCVSS 8.1EG 8.12021-05-06
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.
- CVE-2021-29080HIGHCVSS 8.1EG 8.12021-03-23
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2…
- CVE-2019-12943HIGHCVSS 8.1EG 8.12019-09-10
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names.
- CVE-2018-1000812HIGHCVSS 8.1EG 8.12018-12-20
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that …
- CVE-2018-12579HIGHCVSS 8.1EG 8.12018-08-20
An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8,…
- CVE-2017-0921HIGHCVSS 8.1EG 8.12018-07-03
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromi…
- CVE-2014-6412HIGHCVSS 8.1EG 8.12018-04-12
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
- CVE-2017-8613HIGHCVSS 8.1EG 8.12017-06-29
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege V…
- CVE-2026-60650HIGHCVSS 8.0EG 8.02026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…
- CVE-2026-60648HIGHCVSS 8.0EG 8.02026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…
- CVE-2026-60646HIGHCVSS 8.0EG 8.02026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…
- CVE-2026-46894HIGHCVSS 8.0EG 8.02026-06-17
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …
- CVE-2024-42915HIGHCVSS 8.0EG 8.02024-08-23
A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' p…
- CVE-2024-2463HIGHCVSS 8.0EG 8.02024-03-21
Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →