← Back
CWE-384

412 CVEs • Abstraction: Compound

Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

JSON object

Loading...

CVEs (412)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Snipeitapp
1Snipe It
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an au...Show more
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.Show less
1Namelessmc
1Nameless
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
1Dell
1Wyse Management Suite
Jun 17, 2026
Aug 10, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's...Show more
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.Show less
1Dw
1Megapix Firmware
Jun 17, 2026
Jul 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.
1Synology
1Photo Station
Jun 17, 2026
Jul 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.
1Passport Project
1Passport
Jun 17, 2026
Jul 1, 2022
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
1Silverstripe
1Silverstripe
Jun 17, 2026
Jun 28, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
1Gibbonedu
1Gibbon
Jul 9, 2026
May 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
1Filegator
1Filegator
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Apr 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
1Bbraun
2Datamodule Compactplus
Spacecom
Jun 17, 2026
Apr 14, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sess...Show more
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.Show less
1Fantec
1Mwid25 Ds Firmware
Jun 17, 2026
Apr 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.
1Geon Project
1Geon
Jun 17, 2026
Mar 24, 2022
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session....Show more
Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from other users, spoof that uuid through the browser console and become co-owners of the target session. This issue is patched in version 1.1.0. No known workaround exists.Show less
1Shopware
1Shopware
Jun 17, 2026
Mar 9, 2022
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inc...Show more
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions guest sessions are shared between customers when HTTP cache is enabled. This can lead to inconsistent experiences for guest users. Setups with Varnish are not affected by this issue. This issue has been resolved in version 6.4.8.2. Users unable to upgrade should disable the HTTP Cache.Show less
1Ibm
1Financial Transaction Manager
Jun 17, 2026
Feb 2, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
1Dell
1Emc Appsync
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a different computer, different web browser on the same machine, etc.) to take over an existing session. This does require the attacker to be able to spoof or take over original IP address of the original user's session.Show less
1Pluck Cms
1Pluck
Jun 17, 2026
Dec 10, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access ca...Show more
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.Show less
1Auth0
1Express Openid Connect
Jun 17, 2026
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in....Show more
Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session fixation vulnerabilities. Versions `2.5.2` contains a patch for this issue.Show less