CWE-804: Guessable CAPTCHA
The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.
16 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8546 — atjiu pybbs Verification Code login Captcha
- CVE-2025-10423 — newbee-mall kaptcha mallKaptcha Captcha
- CVE-2026-49953 — Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set
- CVE-2024-23566 — HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead
- CVE-2025-1262 — Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass
- CVE-2026-27411 — WordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerability
- CVE-2026-40935 — WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- CVE-2026-13082 — GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
- CVE-2025-32036 — DNN allows the possibility of bypassing Captcha
- CVE-2024-23567 — HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti
- CVE-2025-40916 — Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha text
Recently published
- CVE-2024-23566 — HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead
- CVE-2024-23567 — HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensiti
- CVE-2026-13082 — GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets
- CVE-2026-49953 — Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set
- CVE-2026-40935 — WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- CVE-2026-27411 — WordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerability
- CVE-2025-10423 — newbee-mall kaptcha mallKaptcha Captcha
- CVE-2025-8546 — atjiu pybbs Verification Code login Captcha
- CVE-2025-40916 — Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha text
- CVE-2025-32036 — DNN allows the possibility of bypassing Captcha
- CVE-2025-1262 — Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass