CWE-620


Unverified Password Change

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.


We have discovered 2,455 live websites that are affected by CWE-620.

Contact us to get more info









CVEs

  • Count - 8



Website Distribution by Country

Number of websites using CWE-620
United States525 websites



Italy190 websites
Germany174 websites
GB125 websites
Spain117 websites
France117 websites
Netherlands95 websites
South Africa59 websites
Poland55 websites
Russia54 websites

Website Distribution by TLD

Number of websites using CWE-620
.com1,024 websites
.it158 websites
.co.uk75 websites
.de74 websites
.nl73 websites
.com.br50 websites
.es49 websites
.pl46 websites
.com.au45 websites
.ru42 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-620
DiscoveredCVEDescriptionWebsites
Jul, 2025CVE-2025-4606 Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover1
Jun, 2025CVE-2025-5482 Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber) Privilege Escalation42
May, 2025CVE-2025-4322 Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover1,912
May, 2025CVE-2025-47938 TYPO3 Vulnerable to Unverified Password Change for Backend Users3
Apr, 2025CVE-2025-3607 Frontend Login and Registration Blocks <= 1.0.7 - Authenticated (Subscriber+) Privilege Escalation via Password Reset3
Mar, 2025CVE-2024-12824 Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change1
Sep, 2024CVE-2024-8794 BA Book Everything <= 1.6.20 - Unauthenticated Arbitrary User Password Reset387
Sep, 2022CVE-2022-3152 Unverified Password Change in phpfusion/phpfusion106
List of the most common CVEs that are part of CWE-620
DiscoveredCVEDescriptionWebsites
May, 2025CVE-2025-4322 Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover1,912
Sep, 2024CVE-2024-8794 BA Book Everything <= 1.6.20 - Unauthenticated Arbitrary User Password Reset387
Sep, 2022CVE-2022-3152 Unverified Password Change in phpfusion/phpfusion106
Jun, 2025CVE-2025-5482 Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber) Privilege Escalation42
Apr, 2025CVE-2025-3607 Frontend Login and Registration Blocks <= 1.0.7 - Authenticated (Subscriber+) Privilege Escalation via Password Reset3
May, 2025CVE-2025-47938 TYPO3 Vulnerable to Unverified Password Change for Backend Users3
Mar, 2025CVE-2024-12824 Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change1
Jul, 2025CVE-2025-4606 Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover1

Websites affected by CWE-620

Top websites that are affected by CWE-620. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com United States***,***
*********.com Germany***,***
**************.com United States***,***
*********.com United States***,***
****.*************.com United States***,***
***************.com United States***,***
*************.com United States*,***,***
************.com United States*,***,***
***************.de Germany*,***,***
*********.fr France*,***,***
See full domain list