CWE-640


Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.


We have discovered 17,376 live websites that are affected by CWE-640.

Contact us to get more info









CVEs

  • Count - 8



Website Distribution by Country

Number of websites using CWE-640
United States8,334 websites



Germany1,379 websites
Iran1,013 websites
GB928 websites
France773 websites
Italy487 websites
Cyprus374 websites
Canada343 websites
Australia297 websites
Netherlands293 websites

Website Distribution by TLD

Number of websites using CWE-640
.com10,101 websites
.org1,014 websites
.net596 websites
.de472 websites
.co.uk434 websites
.it312 websites
.fr257 websites
.com.au253 websites
.nl222 websites
.ca175 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-640
DiscoveredCVEDescriptionWebsites
Dec, 2025CVE-2025-14783 Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect15,039
Nov, 2025CVE-2025-62406 Piwigo is vulnerable to one-click account takeover by modifying the password-reset link551
Sep, 2025CVE-2025-32486 WordPress Material Dashboard plugin <= 1.4.6 - Privilege Escalation Vulnerability1
Feb, 2025CVE-2025-1570 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP393
Nov, 2024CVE-2024-11103 Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover15
Oct, 2024CVE-2024-9305 AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP106
Jan, 2022CVE-2022-22691 Umbraco Password Reset URL Poison885
Aug, 2021CVE-2021-37693 Re-use of email tokens in Discourse387
List of the most common CVEs that are part of CWE-640
DiscoveredCVEDescriptionWebsites
Dec, 2025CVE-2025-14783 Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect15,039
Jan, 2022CVE-2022-22691 Umbraco Password Reset URL Poison885
Nov, 2025CVE-2025-62406 Piwigo is vulnerable to one-click account takeover by modifying the password-reset link551
Feb, 2025CVE-2025-1570 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTP393
Aug, 2021CVE-2021-37693 Re-use of email tokens in Discourse387
Oct, 2024CVE-2024-9305 AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP106
Nov, 2024CVE-2024-11103 Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover15
Sep, 2025CVE-2025-32486 WordPress Material Dashboard plugin <= 1.4.6 - Privilege Escalation Vulnerability1

Websites affected by CWE-640

Top websites that are affected by CWE-640. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***************.eu Netherlands*,***
********.com Germany*,***
**************.com Canada*,***
**********.com United States*,***
********.com United States*,***
************.com United States*,***
**********.com United States*,***
*************.com United States*,***
*************.com United States*,***
See full domain list