Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Volume of CVEs assigned to CWE-384 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
414 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18925CRITICAL Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. | Nov 4, 2018 | 9.8 | 60 | NO | YES |
CVE-2018-11714CRITICAL An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. T | Jun 4, 2018 | 9.8 | 50 | NO | NO |
CVE-2019-10008HIGH Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrato | Apr 24, 2019 | 8.8 | 49 | NO | YES |
CVE-2019-12258HIGH Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | Aug 9, 2019 | 7.5 | 48 | NO | YES |
CVE-2019-18418CRITICAL clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management. | Oct 24, 2019 | 9.8 | 42 | NO | YES |
CVE-2017-12965CRITICAL Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Aug 23, 2017 | 9.8 | 42 | NO | YES |
CVE-2017-6412HIGH In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | Mar 30, 2017 | 8.1 | 40 | NO | YES |
CVE-2025-67446CRITICAL Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By m | Jun 4, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-28242CRITICAL Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack. | Apr 18, 2025 | 9.8 | 38 | NO | YES |
CVE-2009-10007CRITICAL Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks.
Catalyst::Plugin::Authentication does not automatically change the s | Jun 9, 2026 | 9.1 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.