The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Volume of CVEs assigned to CWE-640 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
295 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7028CRITICAL An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5. | Jan 12, 2024 | 9.8 | 99 | YES | YES |
CVE-2019-18818CRITICAL strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js. | Nov 7, 2019 | 9.8 | 94 | NO | YES |
CVE-2017-7615HIGH MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. | Apr 16, 2017 | 8.8 | 92 | NO | YES |
CVE-2024-2862CRITICAL
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
| Mar 25, 2024 | 9.8 | 70 | NO | YES |
CVE-2019-19844CRITICAL Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after cas | Dec 18, 2019 | 9.8 | 60 | NO | YES |
CVE-2025-6216CRITICAL Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations o | Jun 21, 2025 | 9.8 | 54 | NO | YES |
CVE-2025-47646CRITICAL Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery | May 23, 2025 | 9.8 | 49 | NO | YES |
CVE-2017-8295MEDIUM WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a craf | May 4, 2017 | 5.9 | 46 | NO | YES |
CVE-2012-5686CRITICAL ZPanel 10.0.1 has insufficient entropy for its password reset process. | Feb 4, 2020 | 9.8 | 43 | NO | YES |
CVE-2026-13019CRITICAL Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated | Jul 7, 2026 | 9.8 | 42 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.