CWE-384


Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.


We have discovered 9,609 live websites that are affected by CWE-384.

Contact us to get more info









CVEs

  • Count - 12



Website Distribution by Country

Number of websites using CWE-384
United States2,982 websites



China1,247 websites
Germany1,023 websites
Poland364 websites
France345 websites
Italy249 websites
Brazil229 websites
Spain207 websites
Netherlands189 websites
Russia179 websites

Website Distribution by TLD

Number of websites using CWE-384
.com3,417 websites
.de611 websites
.org500 websites
.net370 websites
.pl283 websites
.cn264 websites
.it202 websites
.fr182 websites
.edu173 websites
.nl167 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-384
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-31940 Session Fixation in Chamilo LMS9
Mar, 2026CVE-2026-25101 Session Fixation in Bludit1,257
Feb, 2026CVE-2026-23796 Session Fixation in Quick.Cart347
Feb, 2026CVE-2026-23624 GLPI is vulnerable to session stealing on externally authenticated user change45
Oct, 2025CVE-2025-64100 CKAN Vulnerable to Session Cookie Fixation360
Aug, 2025CVE-2025-55668 Apache Tomcat: session fixation via rewrite valve5,320
Jul, 2025CVE-2025-53102 Discourse's WebAuthn challenge isn't cleared from user session after authentication1,322
Feb, 2025CVE-2025-1412 Session Persistence After User-to-Bot Conversion10
Oct, 2024CVE-2024-48929 Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out2
Jun, 2024CVE-2024-24552 Bludit is Vulnerable to Session Fixation695
List of the most common CVEs that are part of CWE-384
DiscoveredCVEDescriptionWebsites
Aug, 2025CVE-2025-55668 Apache Tomcat: session fixation via rewrite valve5,320
Jul, 2025CVE-2025-53102 Discourse's WebAuthn challenge isn't cleared from user session after authentication1,322
Mar, 2026CVE-2026-25101 Session Fixation in Bludit1,257
Mar, 2017CVE-2016-9125 Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifier...729
Jun, 2024CVE-2024-24552 Bludit is Vulnerable to Session Fixation695
Oct, 2025CVE-2025-64100 CKAN Vulnerable to Session Cookie Fixation360
Feb, 2026CVE-2026-23796 Session Fixation in Quick.Cart347
Feb, 2024CVE-2023-47798 Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay D...208
Feb, 2026CVE-2026-23624 GLPI is vulnerable to session stealing on externally authenticated user change45
Feb, 2025CVE-2025-1412 Session Persistence After User-to-Bot Conversion10

Websites affected by CWE-384

Top websites that are affected by CWE-384. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.de Germany*,***
*******.de Germany*,***
*************.de Germany*,***
***********.ro Romania**,***
****.******.ca Canada**,***
**************.com Canada**,***
**.***.*****.*****.***.com United States**,***
*****************.jetzt Germany**,***
******.******.ca Canada**,***
******.com United States**,***
See full domain list