CWE-613


Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."


We have discovered 4,295 live websites that are affected by CWE-613.

Contact us to get more info









CVEs

  • Count - 10



Website Distribution by Country

Number of websites using CWE-613
United States2,389 websites



France291 websites
Germany283 websites
GB150 websites
Canada122 websites
Japan89 websites
Singapore81 websites
Turkey73 websites
Italy62 websites
Qatar62 websites

Website Distribution by TLD

Number of websites using CWE-613
.com1,671 websites
.org550 websites
.net149 websites
.ca89 websites
.co.uk81 websites
.de63 websites
.io61 websites
.it53 websites
.com.au42 websites
.fr41 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-613
DiscoveredCVEDescriptionWebsites
Oct, 2025CVE-2025-62174 Mastodon allows continued access after password reset via CLI976
Apr, 2025CVE-2025-1968 Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some...1,054
Feb, 2025CVE-2025-24896 Misskey allows token to remain valid in cookie after signing out6
Jan, 2025CVE-2024-11627 : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.Thi...2,000
Feb, 2024CVE-2024-25619 Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodon64
Jan, 2023CVE-2022-46177 Discourse password reset link can lead to in account takeover if user changes to a new email779
Nov, 2022CVE-2022-39234 user session persists even after permanently deleting account in GLPI50
Jun, 2022CVE-2022-31050 Insufficient Session Expiration in TYPO3 Admin Tool1
Jan, 2021CVE-2020-15220 Session fixation4
Jan, 2021CVE-2020-15218 Admin pages are cached and can be embedded4
List of the most common CVEs that are part of CWE-613
DiscoveredCVEDescriptionWebsites
Jan, 2025CVE-2024-11627 : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.Thi...2,000
Apr, 2025CVE-2025-1968 Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some...1,054
Oct, 2025CVE-2025-62174 Mastodon allows continued access after password reset via CLI976
Jan, 2023CVE-2022-46177 Discourse password reset link can lead to in account takeover if user changes to a new email779
Feb, 2024CVE-2024-25619 Destroying OAuth Applications doesn't notify Streaming of Access Tokens being destroyed in mastodon64
Nov, 2022CVE-2022-39234 user session persists even after permanently deleting account in GLPI50
Feb, 2025CVE-2025-24896 Misskey allows token to remain valid in cookie after signing out6
Jan, 2021CVE-2020-15218 Admin pages are cached and can be embedded4
Jan, 2021CVE-2020-15220 Session fixation4
Jun, 2022CVE-2022-31050 Insufficient Session Expiration in TYPO3 Admin Tool1

Websites affected by CWE-613

Top websites that are affected by CWE-613. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Germany***
*********.net GB*,***
***.gov United States*,***
**************.com United States*,***
***.org United States**,***
*******.***.gov United States**,***
*****.org United States**,***
************.com United States**,***
*******.org United States**,***
**********.org United States**,***
See full domain list