← Back
CWE-640

317 CVEs • Abstraction: Base • Likelihood of Exploit: High

Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

JSON object

Loading...

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Os4ed
1Opensis
Jun 17, 2026
Dec 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
1Konzept Ix
1Publixone
Jun 17, 2026
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
1Alfresco
1Reset Password
Jun 17, 2026
Sep 17, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
1Eramba
1Eramba
Jun 17, 2026
Sep 3, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
1Naviwebs
1Navigate Cms
Jun 17, 2026
Jun 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature...Show more
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature returns a not_found message when the provided username or email address does not match a user in the system. This can be used to enumerate users.Show less
1Naviwebs
1Navigate Cms
Jun 17, 2026
Jun 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is sup...Show more
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id).Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Apr 30, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful exec...Show more
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).Show less
1Auto Maskin
3Dcu 210 Firmware
Marine Pro ObserverRp210e Firmware
Jun 17, 2026
Mar 23, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the ori...Show more
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.Show less
1Zpanelcp
1Zpanel
Nov 21, 2024
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZPanel 10.0.1 has insufficient entropy for its password reset process.
1Ushahidi
1Ushahidi
Nov 21, 2024
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
1Ctfd
1Ctfd
Jun 17, 2026
Jan 23, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the...Show more
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one must register with a username identical to the victim's username, but with white space inserted before and/or after the username. This will register the account with the same username as the victim. After initiating a password reset for the new account, CTFd will reset the victim's account password due to the username collision.Show less
1Pyforum Project
1Pyforum
Nov 21, 2024
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
1Intelbras
1Iwr 3000n Firmware
Jun 17, 2026
Jan 5, 2020
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address,...Show more
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.Show less
2Canonical
Djangoproject
2Django
Ubuntu Linux
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters)...Show more
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)Show less
1Progress
1Sitefinity
Jun 17, 2026
Nov 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
1Strapi
1Strapi
Jun 17, 2026
Nov 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
1Craftcms
1Craft Cms
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
1Sitos
1Sitos Six
Jun 17, 2026
Oct 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's acco...Show more
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.Show less
1Jetbrains
1Hub
Jun 17, 2026
Oct 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
1Ttlock
1Ttlock
Jun 17, 2026
Sep 10, 2019
N/A· v4
8.1 HIGH· v3
2.6 LOW· v2
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names.