CWE-916: Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
71 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-5743 — Command Injection Vulnerability
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2025-2265 — Santesoft Sante PACS Server HTTP.db SHA1 Hash Truncation
- CVE-2025-3937 — Use of Password Hash with Insufficient Computational Effort
- CVE-2026-81704 — openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
- CVE-2026-81689 — openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
- CVE-2026-55069 — Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
- CVE-2026-30790 — Improper Restriction of Excessive Authentication Attempts, Use of Password Hash With Insufficient Computational Effort v
- CVE-2026-25861 — QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
- CVE-2026-80211 — FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage
- CVE-2025-41692 — Weak/Predictable root Password
- CVE-2025-24340 — A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker t
- CVE-2025-7789 — Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash
- CVE-2025-13532 — Weak Password Hash in Core Privileged Access Manager (BoKS)
- CVE-2025-26486 — Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash,
- CVE-2026-5040 — Weak Password Hashing Mechanism in TP-Link Deco M5
- CVE-2026-40522 — FrontAccounting < 2.4.20 SQL Injection via rep601.php
- CVE-2024-24553 — Bludit uses SHA1 as Password Hashing Algorithm
- CVE-2026-75112 — OTTO® Fleet Manager – Weak Password Hashing Configuration
- CVE-2026-74871 — openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR
Recently published
- CVE-2026-86670 — aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
- CVE-2026-81704 — openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
- CVE-2026-81689 — openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
- CVE-2026-80211 — FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage
- CVE-2026-53762 — VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-default WOLFCRYPT=1 builds)
- CVE-2026-75112 — OTTO® Fleet Manager – Weak Password Hashing Configuration
- CVE-2026-74871 — openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR
- CVE-2026-49005 — Root password hash exposure vulnerability in ZTE F689 product
- CVE-2026-57310 — Weak password hashing in Windu CMS
- CVE-2026-5040 — Weak Password Hashing Mechanism in TP-Link Deco M5
- CVE-2026-40522 — FrontAccounting < 2.4.20 SQL Injection via rep601.php
- CVE-2026-55069 — Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
- CVE-2026-56272 — Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing
- CVE-2026-9641 — Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
- CVE-2026-25861 — QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
- CVE-2026-44611 — MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computational Effort
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2026-30790 — Improper Restriction of Excessive Authentication Attempts, Use of Password Hash With Insufficient Computational Effort v