CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 6 of 7
- CVE-2020-28186HIGHCVSS 7.3EG 7.32020-12-24
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
- CVE-2016-7038HIGHCVSS 7.3EG 7.32017-01-20
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
- CVE-2024-12604HIGHCVSS 6.5EG 7.32025-03-10
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misus…
- CVE-2026-32103HIGHCVSS 7.2EG 7.22026-03-11
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset-link endpoint allows any authenticated user with admin privileges to generate a password …
- CVE-2026-61049HIGHCVSS 7.1EG 7.12026-07-21
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated atta…
- CVE-2026-53904HIGHCVSS 7.1EG 7.12026-07-01
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as well as previously issued temporary passwords, furthermore, p…
- CVE-2026-30459HIGHCVSS 7.1EG 7.12026-04-16
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.
- CVE-2025-65203HIGHCVSS 7.1EG 7.12025-12-17
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to ac…
- CVE-2025-61977HIGHCVSS 7.0EG 7.02025-10-23
A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery qu…
- CVE-2026-93340MEDIUMCVSS 6.8EG 6.82026-09-21
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in t…
- CVE-2022-22691MEDIUMCVSS 6.8EG 6.82022-01-18
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the…
- CVE-2019-12476MEDIUMCVSS 6.8EG 6.82019-06-17
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client …
- CVE-2017-2614MEDIUMCVSS 6.8EG 6.82018-07-27
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accoun…
- CVE-2026-86260MEDIUMCVSS 6.5EG 6.52026-09-07
A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of t…
- CVE-2026-22723MEDIUMCVSS 6.5EG 6.52026-03-05
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
- CVE-2025-7948MEDIUMCVSS 6.5EG 6.52025-07-22
A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password recovery. The attack can b…
- CVE-2023-3007MEDIUMCVSS 6.5EG 6.52023-05-31
A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Handler. The manipulat…
- CVE-2021-44839MEDIUMCVSS 6.5EG 6.52022-01-18
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user …
- CVE-2019-15749MEDIUMCVSS 6.5EG 6.52019-10-07
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS …
- CVE-2018-12315MEDIUMCVSS 6.5EG 6.52018-12-04
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
- CVE-2017-1000141MEDIUMCVSS 6.5EG 6.52018-01-30
An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior…
- CVE-2016-5997MEDIUMCVSS 6.5EG 6.52016-09-26
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.…
- CVE-2026-61143MEDIUMCVSS 6.4EG 6.42026-07-21
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allow…
- CVE-2025-56748MEDIUMCVSS 6.4EG 6.42025-10-15
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.
- CVE-2022-24892MEDIUMCVSS 6.4EG 6.42022-04-28
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for a…
- CVE-2026-81905MEDIUMCVSS 6.3EG 6.32026-09-10
Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone…
- CVE-2026-82487MEDIUMCVSS 6.3EG 6.32026-08-30
A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be…
- CVE-2021-29038MEDIUMCVSS 6.3EG 6.32024-02-20
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attack…
- CVE-2025-55030MEDIUMCVSS 6.1EG 6.12025-08-19
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks. This vulnerability was fixed in Firefox for i…
- CVE-2021-37541MEDIUMCVSS 6.1EG 6.12021-08-06
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- CVE-2020-11027MEDIUMCVSS 6.1EG 6.12020-04-30
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has bee…
- CVE-2024-43190MEDIUMCVSS 5.9EG 5.92025-07-07
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
- CVE-2019-13240MEDIUMCVSS 5.9EG 5.92019-07-10
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
- CVE-2017-8295MEDIUMCVSS 5.9EG 5.92017-05-04
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arran…
- CVE-2026-7554MEDIUMCVSS 5.6EG 5.62026-05-01
A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attack can be initiated remotely. A high degr…
- CVE-2024-45670MEDIUMCVSS 5.6EG 5.62024-11-14
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.
- CVE-2023-28202MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app firewall setting may not take effect after exiting the Settings app.
- CVE-2022-23172MEDIUMCVSS 5.5EG 5.52022-07-06
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the syst…
- CVE-2025-4552MEDIUMCVSS 5.4EG 5.42025-05-12
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified passwo…
- CVE-2025-1231MEDIUMCVSS 5.4EG 5.42025-02-11
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.
- CVE-2021-36804MEDIUMCVSS 5.4EG 5.42021-08-04
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This…
- CVE-2026-64635MEDIUMCVSS 5.3EG 5.32026-07-30
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the…
- CVE-2026-62517MEDIUMCVSS 5.3EG 5.32026-07-21
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated atta…
- CVE-2026-34198MEDIUMCVSS 5.3EG 5.32026-07-07
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host from any source. The T…
- CVE-2026-9466MEDIUMCVSS 5.3EG 5.32026-05-25
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to …
- CVE-2026-36438MEDIUMCVSS 5.3EG 5.32026-05-18
An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd
- CVE-2026-7652MEDIUMCVSS 5.3EG 5.32026-05-09
The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due to the save_connected_wordpress_user() …
- CVE-2025-14696MEDIUMCVSS 5.3EG 5.32025-12-15
A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulat…
- CVE-2025-10322MEDIUMCVSS 5.3EG 5.32025-09-12
A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible t…
- CVE-2025-4903MEDIUMCVSS 5.3EG 5.32025-05-19
A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the function sub_41F4F0 of the file /H5/webgl.asp?tggl_port=0&remote_management=0&http_passwd=game&exec_service=admin-resta…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →