Threats Tagged 'cwe-640'
View all threats tagged with 'cwe-640'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-640'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-14364: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in themetechmount TrueBooker – Appointment Booking and Scheduler SystemCVE-2026-14364 0 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts, including administrators, and gain access to those accounts. Join the discussion | CVE Database V5 | 08/07/2026, 04:25:56 UTC Added: 08/07/2026, 05:11:57 UTC |
CVE-2026-9273: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in stellarwp Membership Plugin – Kadence MembershipsCVE-2026-9273 0 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover. Join the discussion | CVE Database V5 | 08/05/2026, 04:25:27 UTC Added: 08/05/2026, 05:41:51 UTC |
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to… (CVE-2026-64635)CVE-2026-64635 0 An improper handling vulnerability exists in the Forgot Password function of Veeam Service Provider Console involving the returnUrl parameter. This flaw allows an unauthenticated attacker to manipulate the domain of the password reset link sent via email. If a targeted user clicks the malicious link, the reset code is sent to an attacker-controlled host, enabling account takeover. The vulnerability is classified under CWE-640 and has a moderate severity rating. No affected versions or patch information are provided. Join the discussion | GCVE Database | 07/30/2026, 06:32:37 UTC Added: 07/30/2026, 15:50:30 UTC |
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. (CVE-2026-18363)CVE-2026-18363 0 A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able to obtain a valid password reset token could reuse it to perform an unauthorised password reset and compromise the affected account. Join the discussion | GCVE Database | 07/30/2026, 12:32:18 UTC Added: 07/30/2026, 15:50:10 UTC |
CVE-2026-53595: CWE-178: Improper Handling of Case Sensitivity in freescout-help-desk freescoutCVE-2026-53595 0 FreeScout versions prior to 1.8.224 contain a critical vulnerability in the public user setup endpoint that allows an unauthenticated attacker to overwrite the email and password of the lowest-id activated user account and log in as that user. This occurs due to improper handling of case sensitivity and trailing spaces in the invite_hash field on MySQL/MariaDB, combined with a flawed decryption check that allows bypassing the expiry guard. The vulnerability is fixed in version 1.8.224. Join the discussion | CVE Database V5 | 07/20/2026, 20:14:59 UTC Added: 07/20/2026, 20:27:18 UTC |
CVE-2026-15155: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in wpdevteam Essential Addons for Elementor – Popular Elementor Templates & WidgetsCVE-2026-15155 0 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover. Join the discussion | CVE Database V5 | 07/11/2026, 05:35:49 UTC Added: 07/11/2026, 06:33:04 UTC |
CVE-2026-7655: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in surecart SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & PaymentsCVE-2026-7655 0 The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known. Join the discussion | CVE Database V5 | 07/11/2026, 04:32:59 UTC Added: 07/11/2026, 05:33:15 UTC |
Showing 1 to 7 of 7 results