CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
339 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 7 of 7
- CVE-2025-0331MEDIUMCVSS 5.3EG 5.32025-01-09
A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. T…
- CVE-2024-8692MEDIUMCVSS 5.3EG 5.32024-09-11
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The explo…
- CVE-2024-0491MEDIUMCVSS 5.3EG 5.32024-01-13
A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is…
- CVE-2024-0425MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be in…
- CVE-2023-50172MEDIUMCVSS 5.3EG 5.32024-01-10
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pas…
- CVE-2023-46138MEDIUMCVSS 5.3EG 5.32023-10-31
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycompany[.]com`, and users reset their pass…
- CVE-2023-44399MEDIUMCVSS 5.3EG 5.32023-10-10
ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. While this settings…
- CVE-2023-28821MEDIUMCVSS 5.3EG 5.32023-04-28
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
- CVE-2021-36436MEDIUMCVSS 5.3EG 5.32023-04-20
An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoint.
- CVE-2022-30332MEDIUMCVSS 5.3EG 5.32023-01-10
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows re…
- CVE-2022-34530MEDIUMCVSS 5.3EG 5.32022-08-01
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
- CVE-2022-23619MEDIUMCVSS 5.3EG 5.32022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the…
- CVE-2021-36095MEDIUMCVSS 5.3EG 5.32021-09-06
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
- CVE-2021-37693MEDIUMCVSS 5.3EG 5.32021-08-13
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the…
- CVE-2020-14016MEDIUMCVSS 5.3EG 5.32020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature returns a not_foun…
- CVE-2019-14955MEDIUMCVSS 5.3EG 5.32019-10-01
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
- CVE-2018-10210MEDIUMCVSS 5.3EG 5.32018-04-25
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
- CVE-2017-8385MEDIUMCVSS 5.3EG 5.32017-05-01
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
- CVE-2025-36579MEDIUMCVSS 5.1EG 5.12026-04-16
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
- CVE-2020-5361MEDIUMCVSS 5.1EG 5.12021-01-04
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can gene…
- CVE-2026-62486MEDIUMCVSS 5.0EG 5.02026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated atta…
- CVE-2026-105785MEDIUMCVSS 4.8EG 4.82026-10-05
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-…
- CVE-2026-9609MEDIUMCVSS 4.7EG 4.72026-05-27
A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available a…
- CVE-2021-39919MEDIUMCVSS 4.4EG 4.42021-12-13
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged wh…
- CVE-2026-4136MEDIUMCVSS 4.3EG 4.32026-03-20
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' …
- CVE-2025-14783MEDIUMCVSS 4.3EG 4.32025-12-31
The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This m…
- CVE-2025-3849MEDIUMCVSS 4.3EG 4.32025-04-22
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password chan…
- CVE-2023-5959MEDIUMCVSS 4.3EG 4.32023-11-11
A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak passwo…
- CVE-2022-42807MEDIUMCVSS 4.3EG 4.32023-06-23
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key
- CVE-2026-19361LOWCVSS 3.7EG 3.72026-08-09
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be laun…
- CVE-2026-10169LOWCVSS 3.7EG 3.72026-05-31
A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controlle…
- CVE-2024-9907LOWCVSS 3.7EG 3.72024-10-13
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation lead…
- CVE-2024-36407LOWCVSS 3.7EG 3.72024-06-10
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new passw…
- CVE-2015-3189LOWCVSS 3.7EG 3.72017-05-25
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current emai…
- CVE-2025-2093LOWCVSS 3.1EG 3.12025-03-07
A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change-password.php. The manipulation of the argumen…
- CVE-2021-39899LOWCVSS 2.9EG 2.92021-10-04
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by steali…
- CVE-2026-2543LOWCVSS 2.7EG 2.72026-02-16
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverifie…
- CVE-2025-7881LOWCVSS 2.7EG 2.72025-07-20
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument code leads to weak pa…
- CVE-2024-50356UnratedEG not assessed2024-10-31
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even tho…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →