CWE-640: Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
166 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-6216 — Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
- CVE-2025-47646 — WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2026-32865 — OPEXUS eComplaint and eCase insecure password reset
- CVE-2026-28268 — Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
- CVE-2026-26273 — Known affected by Account Takeover via Password Reset Token Leakage
- CVE-2025-32486 — WordPress Material Dashboard plugin <= 1.4.6 - Privilege Escalation Vulnerability
- CVE-2025-31380 — WordPress Paid Videochat Turnkey Site plugin <= 7.3.11 - Broken Authentication Vulnerability
- CVE-2025-12866 — Hundred Plus|EIP Plus - Weak Password Recovery Mechanism
- CVE-2025-10127 — Daikin Europe N.V Security Gateway Weak Password Recovery Mechanism for Forgotten Password
- CVE-2024-5404 — ifm: moneo prone to weak password recovery mechanism
- CVE-2024-47547 — Ruijie Reyee OS Weak Password Recovery Mechanism for Forgotten Password
- CVE-2025-64113 — Emby Server allows attackers to gain administrative server access without preconditions
- CVE-2026-2564 — Intelbras VIP 3260 Z IA OutsideCmd password recovery
- CVE-2026-34751 — Payload has Unvalidated Input in Password Recovery Endpoints
- CVE-2025-53373 — Natours has a 1 Click Account take over on reset password via Host Header injection
- CVE-2024-32642 — Host header poisoning allows account takeover via password reset email
- CVE-2024-27899 — Security misconfiguration vulnerability in SAP NetWeaver AS Java User Management Engine
- CVE-2024-22454 — Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgot
- CVE-2025-53704 — MAXHUB Pivot Weak Password Recovery Mechanism for Forgotten Password
Recently published
- CVE-2026-6285 — Improper Authentication in Ankaref's LIBRID/LIBREF
- CVE-2026-86260 — sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change
- CVE-2026-84699 — Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
- CVE-2026-82487 — Beetel 450TC3 password recovery
- CVE-2026-19632 — TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
- CVE-2026-80196 — Kimai before 2.58.0 Authentication Bypass via Password Reset Link
- CVE-2026-77264 — Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2026-15689 — Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
- CVE-2026-12949 — Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter
- CVE-2026-72856 — Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email
- CVE-2026-66691 — WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability
- CVE-2026-61967 — WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability
- CVE-2026-12571 — Authentication Bypass Leading to Account Takeover
- CVE-2026-72772 — n8n before 2.32.1 Authentication Bypass via Token Exchange
- CVE-2026-19361 — macrozheng mall mall-portal getAuthCode password recovery
- CVE-2026-14364 — TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'
- CVE-2026-9273 — Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover
- CVE-2026-18363 — Weak password recovery mechanism in osTicket by Enhancesoft LLC
- CVE-2026-64635 — Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an