CWE-640 · 276 records
Weak Password Recovery Mechanism for Forgotten Password
CVEs in this class
276 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2023-7028Weaponized | Weak Password Recovery Mechanism for Forgotten Password in GitLabgitlab · gitlab · CWE-640 | Critical9.8 | KEV | 94.6% | Jan 12, 2024 |
68This week | CVE-2019-18818Weaponized | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-pstrapi · strapi · CWE-640 | Critical9.8 | — | 97.6% | Nov 7, 2019 |
62This week | CVE-2017-7615Weaponized | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.mantisbt · mantisbt · CWE-640 | High8.8 | — | 91.1% | Apr 16, 2017 |
55Plan | CVE-2019-19844Proof of concept | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.djangoproject · django · CWE-640 | Critical9.8 | — | 53.6% | Dec 18, 2019 |
53Plan | CVE-2025-6216Proof of concept | Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerabilityalltena · allegra · CWE-640 | Critical9.8 | — | 47.8% | Jun 20, 2025 |
46Plan | CVE-2025-47646Proof of concept | WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerabilitygilblas ngunte possi · psw front-end login & registration · CWE-640 | Critical9.8 | — | 24.7% | May 23, 2025 |
42Plan | CVE-2026-19632Proof of concept | TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosurecozmoslabs · translatepress – translate multilingual sites with ai translation · CWE-640 | Critical9.8 | — | 9.0% | Aug 26, 2026 |
41Plan | CVE-2017-17097Proof of concept | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticagps-server · gps tracking software · CWE-640 | Critical9.8 | — | 6.9% | Jan 2, 2018 |
40Plan | CVE-2012-5686Proof of concept | ZPanel 10.0.1 has insufficient entropy for its password reset process.zpanelcp · zpanel · CWE-640 | Critical9.8 | — | 4.8% | Feb 4, 2020 |
40Plan | CVE-2018-19488No exploit | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the adminwp-jobhunt project · wp-jobhunt · CWE-640 | Critical9.8 | — | 4.1% | Mar 21, 2019 |
40Plan | CVE-2018-7811No exploit | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whischneider-electric · modicom m340 firmware · CWE-640 | Critical9.8 | — | 3.5% | Nov 30, 2018 |
40Plan | CVE-2018-12421No exploit | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a craftedltb-project · ldap tool box self service password · CWE-640 | Critical9.8 | — | 2.8% | Jun 14, 2018 |
40Plan | CVE-2018-7809No exploit | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whischneider-electric · modicom m340 firmware · CWE-640 | Critical9.8 | — | 2.5% | Nov 30, 2018 |
40Plan | CVE-2015-4689No exploit | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,ellucian · banner student · CWE-640 | Critical9.8 | — | 2.3% | Sep 11, 2017 |
40Plan | CVE-2019-11393No exploit | An issue was discovered in /admin/users/update in M/Monit before 3.7.3.tildeslash · monit · CWE-640 | Critical9.8 | — | 2.1% | Apr 22, 2019 |
40Plan | CVE-2021-22763No exploit | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic schneider-electric · powerlogic pm5560 firmware · CWE-640 | Critical9.8 | — | 1.9% | Jun 11, 2021 |
40Plan | CVE-2018-17298No exploit | An issue was discovered in Enalean Tuleap before 10.5.enalean · tuleap · CWE-640 | Critical9.8 | — | 1.8% | Sep 21, 2018 |
40Plan | CVE-2019-15929No exploit | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibilcraftcms · craft cms · CWE-640 | Critical9.8 | — | 1.8% | Oct 24, 2019 |
40Plan | CVE-2022-23855No exploit | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.saviynt · enterprise identity cloud · CWE-640 | Critical9.8 | — | 1.7% | Jan 23, 2022 |
40Plan | CVE-2024-8878No exploit | Unauthenticated Password Resetriello-ups · netman 204 firmware · CWE-640 | Critical10.0 | — | 1.3% | Sep 24, 2024 |
40Plan | CVE-2025-63314Proof of concept | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset theddsn · cm3 acora cms · CWE-640 | Critical10.0 | — | 0.3% | Jan 12, 2026 |
39Monitor | CVE-2018-18871No exploit | Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (gigasetpro · maxwell basic firmware · CWE-640 | Critical9.8 | — | 1.7% | Dec 20, 2018 |
39Monitor | CVE-2017-2766No exploit | EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum emc · documentum eroom · CWE-640 | Critical9.8 | — | 1.6% | Feb 3, 2017 |
39Monitor | CVE-2018-16988No exploit | An issue was discovered in Open XDMoD through 7.5.0.buffalo · open xdmod · CWE-640 | Critical9.8 | — | 1.6% | May 2, 2019 |
39Monitor | CVE-2021-28293No exploit | Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.seceon · aisiem · CWE-640 | Critical9.8 | — | 1.6% | Jun 8, 2021 |
- CVE-2023-702897Now
Weak Password Recovery Mechanism for Forgotten Password in GitLab
CriticalCVSS 9.8KEVWeaponizedEPSS 95%gitlab · gitlabJan 12, 2024
- CVE-2019-1881868This week
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p
CriticalCVSS 9.8WeaponizedEPSS 98%strapi · strapiNov 7, 2019
- CVE-2017-761562This week
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
HighCVSS 8.8WeaponizedEPSS 91%mantisbt · mantisbtApr 16, 2017
- CVE-2019-1984455Plan
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.
CriticalCVSS 9.8Proof of conceptEPSS 54%djangoproject · djangoDec 18, 2019
- CVE-2025-621653Plan
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 48%alltena · allegraJun 20, 2025
- CVE-2025-4764646Plan
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 25%gilblas ngunte possi · psw front-end login & registrationMay 23, 2025
- CVE-2026-1963242Plan
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
CriticalCVSS 9.8Proof of conceptEPSS 9%cozmoslabs · translatepress – translate multilingual sites with ai translationAug 26, 2026
- CVE-2017-1709741Plan
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthentica
CriticalCVSS 9.8Proof of conceptEPSS 7%gps-server · gps tracking softwareJan 2, 2018
- CVE-2012-568640Plan
ZPanel 10.0.1 has insufficient entropy for its password reset process.
CriticalCVSS 9.8Proof of conceptEPSS 5%zpanelcp · zpanelFeb 4, 2020
- CVE-2018-1948840Plan
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin
CriticalCVSS 9.8No exploitEPSS 4%wp-jobhunt project · wp-jobhuntMar 21, 2019
- CVE-2018-781140Plan
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi
CriticalCVSS 9.8No exploitEPSS 3%schneider-electric · modicom m340 firmwareNov 30, 2018
- CVE-2018-1242140Plan
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted
CriticalCVSS 9.8No exploitEPSS 3%ltb-project · ldap tool box self service passwordJun 14, 2018
- CVE-2018-780940Plan
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi
CriticalCVSS 9.8No exploitEPSS 2%schneider-electric · modicom m340 firmwareNov 30, 2018
- CVE-2015-468940Plan
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,
CriticalCVSS 9.8No exploitEPSS 2%ellucian · banner studentSep 11, 2017
- CVE-2019-1139340Plan
An issue was discovered in /admin/users/update in M/Monit before 3.7.3.
CriticalCVSS 9.8No exploitEPSS 2%tildeslash · monitApr 22, 2019
- CVE-2021-2276340Plan
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic
CriticalCVSS 9.8No exploitEPSS 2%schneider-electric · powerlogic pm5560 firmwareJun 11, 2021
- CVE-2018-1729840Plan
An issue was discovered in Enalean Tuleap before 10.5.
CriticalCVSS 9.8No exploitEPSS 2%enalean · tuleapSep 21, 2018
- CVE-2019-1592940Plan
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil
CriticalCVSS 9.8No exploitEPSS 2%craftcms · craft cmsOct 24, 2019
- CVE-2022-2385540Plan
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.
CriticalCVSS 9.8No exploitEPSS 2%saviynt · enterprise identity cloudJan 23, 2022
- CVE-2024-887840Plan
Unauthenticated Password Reset
CriticalCVSS 10.0No exploitEPSS 1%riello-ups · netman 204 firmwareSep 24, 2024
- CVE-2025-6331440Plan
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the
CriticalCVSS 10.0Proof of conceptEPSS 0%ddsn · cm3 acora cmsJan 12, 2026
- CVE-2018-1887139Monitor
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (
CriticalCVSS 9.8No exploitEPSS 2%gigasetpro · maxwell basic firmwareDec 20, 2018
- CVE-2017-276639Monitor
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum
CriticalCVSS 9.8No exploitEPSS 2%emc · documentum eroomFeb 3, 2017
- CVE-2018-1698839Monitor
An issue was discovered in Open XDMoD through 7.5.0.
CriticalCVSS 9.8No exploitEPSS 2%buffalo · open xdmodMay 2, 2019
- CVE-2021-2829339Monitor
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.
CriticalCVSS 9.8No exploitEPSS 2%seceon · aisiemJun 8, 2021