CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 5 of 7
- CVE-2024-24903HIGHCVSS 8.0EG 8.02024-03-01
Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unaut…
- CVE-2021-25961HIGHCVSS 8.0EG 8.02021-09-29
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly cr…
- CVE-2023-34357HIGHCVSS 7.8EG 7.82023-09-07
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration d…
- CVE-2023-29145HIGHCVSS 7.8EG 7.82023-06-30
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an execut…
- CVE-2023-31287HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be…
- CVE-2021-27654HIGHCVSS 7.8EG 7.82022-01-28
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
- CVE-2020-5899HIGHCVSS 7.8EG 7.82020-07-01
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the data…
- CVE-2017-8916HIGHCVSS 7.8EG 7.82018-01-31
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
- CVE-2026-53646HIGHCVSS 7.7EG 7.72026-07-06
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already exists for a client (from a previous unexpired reset request), subsequent calls to the `r…
- CVE-2026-61181HIGHCVSS 7.6EG 7.62026-07-21
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows l…
- CVE-2026-6285HIGHCVSS 7.5EG 7.52026-09-10
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.
- CVE-2026-80196HIGHCVSS 7.5EG 7.52026-08-25
Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or c…
- CVE-2026-60658HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated …
- CVE-2026-7459HIGHCVSS 7.5EG 7.52026-05-30
The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event…
- CVE-2023-53958HIGHCVSS 7.5EG 7.52025-12-19
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sen…
- CVE-2025-53704HIGHCVSS 7.5EG 7.52025-12-04
The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
- CVE-2024-5277HIGHCVSS 7.5EG 7.52024-06-06
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the p…
- CVE-2024-33530HIGHCVSS 7.5EG 7.52024-05-02
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
- CVE-2023-5296HIGHCVSS 7.5EG 7.52023-09-29
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation le…
- CVE-2023-3222HIGHCVSS 7.5EG 7.52023-09-04
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could…
- CVE-2023-26615HIGHCVSS 7.5EG 7.52023-06-28
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
- CVE-2022-25027HIGHCVSS 7.5EG 7.52023-01-12
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
- CVE-2020-12067HIGHCVSS 7.5EG 7.52022-12-26
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
- CVE-2021-43498HIGHCVSS 7.5EG 7.52022-04-08
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
- CVE-2022-0777HIGHCVSS 7.5EG 7.52022-03-01
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
- CVE-2021-44037HIGHCVSS 7.5EG 7.52021-11-19
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
- CVE-2021-36708HIGHCVSS 7.5EG 7.52021-08-06
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.
- CVE-2021-33321HIGHCVSS 7.5EG 7.52021-08-03
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.passwo…
- CVE-2020-27408HIGHCVSS 7.5EG 7.52020-12-04
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
- CVE-2020-15949HIGHCVSS 7.5EG 7.52020-11-05
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
- CVE-2020-26061HIGHCVSS 7.5EG 7.52020-10-05
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questio…
- CVE-2020-14015HIGHCVSS 7.5EG 7.52020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system w…
- CVE-2009-5025HIGHCVSS 7.5EG 7.52020-01-15
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
- CVE-2018-0696HIGHCVSS 7.5EG 7.52019-02-13
OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.
- CVE-2015-7257HIGHCVSS 7.5EG 7.52017-08-24
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username par…
- CVE-2017-7629HIGHCVSS 7.5EG 7.52017-06-15
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
- CVE-2017-9543HIGHCVSS 7.5EG 7.52017-06-12
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.
- CVE-2017-7731HIGHCVSS 7.5EG 7.52017-05-27
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.
- CVE-2016-8716HIGHCVSS 7.5EG 7.52017-04-12
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits th…
- CVE-2017-5594HIGHCVSS 7.5EG 7.52017-01-25
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. …
- CVE-2016-2349HIGHCVSS 7.5EG 7.52016-12-21
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
- CVE-2016-5996HIGHCVSS 7.5EG 7.52016-09-26
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.…
- CVE-2015-10071HIGHCVSS 2.6EG 7.52023-01-19
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak password recovery. …
- CVE-2026-40585HIGHCVSS 7.4EG 7.42026-04-21
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-character CSPRNG token is generated and stored alongside a password_reset_at timestamp. However, the token redemption functio…
- CVE-2023-43650HIGHCVSS 7.4EG 7.42023-09-27
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer provides a feature allowing users to reset forgotten passwo…
- CVE-2023-35134HIGHCVSS 7.4EG 7.42023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.
- CVE-2026-90522HIGHCVSS 7.3EG 7.32026-09-13
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipul…
- CVE-2026-56308HIGHCVSS 7.3EG 7.32026-07-12
Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change th…
- CVE-2026-15479HIGHCVSS 7.3EG 7.32026-07-12
A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newP…
- CVE-2026-12066HIGHCVSS 7.3EG 7.32026-06-12
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument userna…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →