CWE-640


Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.


We have discovered 10,094 live websites that are affected by CWE-640.

Contact us to get more info









CVEs

  • Count - 12



Website Distribution by Country

Number of websites using CWE-640
United States4,411 websites



Germany758 websites
Iran719 websites
GB544 websites
France406 websites
Italy314 websites
Cyprus232 websites
Canada218 websites
Denmark176 websites
Australia169 websites

Website Distribution by TLD

Number of websites using CWE-640
.com5,501 websites
.org552 websites
.net321 websites
.de249 websites
.co.uk234 websites
.it214 websites
.com.au156 websites
.fr129 websites
.dk126 websites
.nl126 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-640
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-33707 Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms9
Feb, 2026CVE-2026-27593 Statamic is vulnerable to account takeover via password reset link injection1
Dec, 2025CVE-2025-14783 Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect8,335
Nov, 2025CVE-2025-62406 Piwigo is vulnerable to one-click account takeover by modifying the password-reset link141
Feb, 2025CVE-2025-1570 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP334
Jan, 2025CVE-2024-11350 AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover2
Nov, 2024CVE-2024-11103 Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover16
Oct, 2024CVE-2024-9305 AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP35
Jun, 2024CVE-2024-6125 Login with phone number <= 1.7.34 - Insecure Password Reset Mechanism2
Jun, 2024CVE-2023-7264 Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism44
List of the most common CVEs that are part of CWE-640
DiscoveredCVEDescriptionWebsites
Dec, 2025CVE-2025-14783 Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect8,335
Jan, 2022CVE-2022-22691 Umbraco Password Reset URL Poison842
Aug, 2021CVE-2021-37693 Re-use of email tokens in Discourse335
Feb, 2025CVE-2025-1570 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP334
Nov, 2025CVE-2025-62406 Piwigo is vulnerable to one-click account takeover by modifying the password-reset link141
Jun, 2024CVE-2023-7264 Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism44
Oct, 2024CVE-2024-9305 AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP35
Nov, 2024CVE-2024-11103 Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover16
Apr, 2026CVE-2026-33707 Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms9
Jun, 2024CVE-2024-6125 Login with phone number <= 1.7.34 - Insecure Password Reset Mechanism2

Websites affected by CWE-640

Top websites that are affected by CWE-640. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.eu Netherlands*,***
**************.com Canada*,***
**********.com United States*,***
*********.com United States*,***
*********.com United States*,***
******.*********.com United States*,***
*************.com United States*,***
*********.com United States*,***
**********.com Australia**,***
***********.com United States**,***
See full domain list