CWE-384: CWE-384

72
Total CVEs
24
Critical
26
High
7.8
Avg CVSS

Yearly Trend

2026
8
2025
25
2024
15
2023
14
2022
5

Top Affected Vendors

1 Ibm 3
2 Apache 3
3 Dbbroadcast 3
4 Phpgurukul 2
5 Jenkins 2
6 Hcltech 2
7 Glpi Project 1
8 Video Management System Project 1
9 Hpe 1
10 Easyappointments 1

All CWE-384 CVEs (72)

CVE-2024-11317
10.0

CVE-2024-11317 is a session fixation vulnerability in ABB ASPECT, NEXUS, and MATRIX series products that allows attackers to set a user's session ID b...

Dec 5, 2024
CVE-2024-38513
10.0

This vulnerability in GoFiber's session middleware allows attackers to supply their own session_id, enabling session fixation attacks and unauthorized...

Jul 1, 2024
CVE-2021-20151
10.0

This vulnerability allows session hijacking on Trendnet AC2600 routers by exploiting IP-based session management instead of proper token verification....

Dec 30, 2021
CVE-2026-23796
9.8

Quick.Cart e-commerce software has a session fixation vulnerability where an attacker can set a victim's session ID before authentication, then hijack...

Feb 5, 2026
CVE-2025-59841
9.8

Flag Forge CTF platform versions 2.2.0 through 2.3.0 have a session invalidation vulnerability where authenticated users can continue accessing protec...

Sep 25, 2025
CVE-2025-53102
9.8

Discourse versions before 3.4.7 and 3.5.0.beta8 have a session fixation vulnerability in WebAuthn 2FA implementation. When users authenticate with phy...

Jul 29, 2025
CVE-2025-28238
9.8

This vulnerability allows attackers to hijack active user sessions in Elber REBLE310 devices running firmware v5.5.1.R. Attackers can impersonate legi...

Apr 18, 2025
CVE-2022-40916
9.8

CVE-2022-40916 is a session fixation vulnerability in Tiny File Manager v2.4.7 and below that allows attackers to hijack user sessions by fixing sessi...

Feb 6, 2025
CVE-2024-57052
9.8

A session fixation vulnerability in YoudianCMS v9.5.20 and earlier allows remote attackers to escalate privileges by manipulating the sessionID parame...

Jan 27, 2025
CVE-2024-13279
9.8

A session fixation vulnerability in Drupal's Two-factor Authentication (TFA) module allows attackers to hijack user sessions by fixing session IDs bef...

Jan 9, 2025
CVE-2024-8643
9.8

A session fixation vulnerability in Oceanic Software ValeApp allows attackers to hijack user sessions and perform brute force attacks. This affects al...

Sep 27, 2024
CVE-2024-23679
9.8

Enonic XP versions before 7.7.4 have a session fixation vulnerability where session attributes aren't properly invalidated. This allows remote unauthe...

Jan 19, 2024
CVE-2023-48929
9.8

This session fixation vulnerability in Franklin Fueling Systems System Sentinel AnyWare allows attackers to hijack user sessions by manipulating the '...

Dec 8, 2023
CVE-2023-42322
9.8

CVE-2023-42322 is an insecure permissions vulnerability in iCMS v7.0.16 that allows remote attackers to access sensitive information without authentic...

Sep 20, 2023
CVE-2023-28316
9.8

A session fixation vulnerability in Rocket.Chat's 2FA implementation allows attackers to maintain access to compromised accounts even after 2FA is ena...

May 9, 2023
CVE-2021-36394
9.8

CVE-2021-36394 is a critical remote code execution vulnerability in Moodle's Shibboleth authentication plugin. Attackers can execute arbitrary code on...

Mar 6, 2023
CVE-2021-38869
9.8

IBM QRadar SIEM fails to automatically log users out after exceeding idle timeout in certain situations, allowing unauthorized session persistence. Th...

Apr 27, 2022
CVE-2021-41553
9.8

CVE-2021-41553 is a session fixation vulnerability in ARCHIBUS Web Central that allows attackers to hijack user sessions by setting arbitrary JSESSION...

Oct 5, 2021
CVE-2021-39290
9.8

This vulnerability allows session fixation attacks on NetModule networking devices, enabling attackers to hijack user sessions by setting a known PHPS...

Aug 23, 2021
CVE-2025-69602
9.1

A session fixation vulnerability in 66biolinks v62.0.0 allows attackers to hijack authenticated user sessions by setting or predicting session IDs bef...

Jan 28, 2026
CVE-2025-45953
9.1

A session hijacking vulnerability in PHPGurukul Hostel Management System 2.1 allows attackers to steal user sessions and impersonate legitimate users....

Apr 28, 2025
CVE-2025-27661
9.1

This CVE describes a session fixation vulnerability in Vasion Print (formerly PrinterLogic) that allows attackers to hijack user sessions. Attackers c...

Mar 5, 2025
CVE-2023-52268
9.1

CVE-2023-52268 is an authentication bypass vulnerability in FreeScout's End-User Portal module where attackers can send session tokens to the /auth en...

Nov 12, 2024
CVE-2024-23590
9.1

This CVE describes a session fixation vulnerability in Apache Kylin that allows attackers to hijack user sessions by fixing session identifiers before...

Nov 4, 2024
CVE-2023-53776
8.8

This authentication bypass vulnerability in Screen SFT DAB 1.9.3 allows attackers to reuse IP-bound session identifiers to perform unauthorized operat...

Dec 10, 2025
CVE-2024-13967
8.8

This vulnerability allows attackers to bypass authentication and access the configuration web page of EIBPORT devices without proper credentials. It a...

Jun 4, 2025
CVE-2024-24552
8.8

CVE-2024-24552 is a session fixation vulnerability in Bludit CMS that allows attackers to hijack user sessions by tricking victims into using attacker...

Jun 24, 2024
CVE-2023-0897
8.8

Sielco PolyEco1000 devices have a session hijack vulnerability where attackers can brute-force session cookies and intercept unencrypted sessions. Thi...

Oct 26, 2023
CVE-2023-37946
8.8

The Jenkins OpenShift Login Plugin vulnerability allows session fixation attacks where previous sessions aren't invalidated upon new login. This enabl...

Jul 12, 2023
CVE-2023-34656
8.8

This vulnerability allows attackers to escalate privileges by exploiting JSESSION ID issues in Xiamen Si Xin Communication Technology Video management...

Jun 29, 2023
CVE-2023-32997
8.8

The Jenkins CAS Plugin 1.6.2 and earlier fails to invalidate previous user sessions upon login, allowing session fixation attacks. This vulnerability ...

May 16, 2023
CVE-2023-2105
8.8

This session fixation vulnerability in easyappointments allows attackers to hijack user sessions by fixing session IDs before authentication. It affec...

Apr 15, 2023
CVE-2022-31888
8.8

This CVE describes a session fixation vulnerability in osTicket's authentication system. Attackers can fixate session IDs before user login, potential...

Apr 5, 2023
CVE-2020-35229
8.8

This vulnerability allows attackers with network access to reuse authentication tokens indefinitely on affected NETGEAR switches, effectively bypassin...

Mar 10, 2021
CVE-2023-53741
8.1

Screen SFT DAB 1.9.3 has a weak session management vulnerability where attackers can bypass authentication by reusing IP-bound session identifiers. Th...

Dec 10, 2025
CVE-2023-6913
8.1

A session hijacking vulnerability in Imou Life app version 6.7.0 allows attackers to hijack user accounts through QR code functionality. The vulnerabi...

Dec 19, 2023
CVE-2023-29019
8.1

CVE-2023-29019 is a session fixation vulnerability in @fastify/passport that allows attackers to hijack user sessions. Applications using @fastify/pas...

Apr 21, 2023
CVE-2022-22681
8.1

This session fixation vulnerability in Synology Photo Station allows attackers to bypass access controls by manipulating session identifiers. Attacker...

Jul 6, 2022
CVE-2025-29928
8.0

authentik versions prior to 2024.12.4 and 2025.2.3 have a session management vulnerability when configured with database session storage. Attackers wi...

Mar 28, 2025
CVE-2023-40273
8.0

This session fixation vulnerability in Apache Airflow allows authenticated users to maintain access to the webserver even after their password has bee...

Aug 23, 2023
CVE-2023-50176
7.5

This session fixation vulnerability in Fortinet FortiOS allows attackers to hijack user sessions via phishing SAML authentication links. Attackers can...

Nov 12, 2024
CVE-2022-34536
7.5

This vulnerability in Digital Watchdog DW MEGApix IP cameras allows attackers to access the core log file and hijack sessions by crafting a malicious ...

Jul 19, 2022
CVE-2022-26591
7.5

This vulnerability allows unauthenticated attackers to download arbitrary files from FANTEC MWiD25-DS network attached storage devices. Attackers can ...

Apr 6, 2022
CVE-2021-31745
7.5

CVE-2021-31745 is a session fixation vulnerability in Pluck-CMS that allows attackers to maintain unauthorized access even after password resets. This...

Dec 10, 2021
CVE-2026-2177
7.3

CVE-2026-2177 is a session fixation vulnerability in SourceCodester Prison Management System 1.0 that allows attackers to hijack user sessions by fixi...

Feb 8, 2026
CVE-2024-25977
7.3

This vulnerability allows session fixation attacks where an attacker can set a victim's session token before login, then hijack their authenticated se...

May 29, 2024
CVE-2024-56529
7.1

Mailcow email server has a session fixation vulnerability where attackers can set session cookies on victim browsers when HSTS is disabled. After vict...

Jan 28, 2025
CVE-2024-7341
7.1

This CVE describes a session fixation vulnerability in Keycloak's SAML adapters where session IDs aren't regenerated during login, even when configure...

Sep 9, 2024
CVE-2022-24781
7.1

CVE-2022-24781 is a session fixation vulnerability in the Geon board game that allows malicious users to spoof other users' UUIDs through browser cons...

Mar 24, 2022
CVE-2023-24477
7.0

This vulnerability allows an authenticated local attacker to potentially access another user's session after logout in Guardian/CMC software. The issu...

Aug 9, 2023

About CWE-384 (CWE-384)

Our database tracks 72 CVEs classified as CWE-384, with 24 rated critical and 26 rated high severity. The average CVSS score for CWE-384 vulnerabilities is 7.8.

External reference: View CWE-384 on MITRE CWE →

Monitor CWE-384 Vulnerabilities

Get alerted when new CWE-384 CVEs affect your infrastructure.

Start Monitoring Free