CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2026-41839
MEDIUM
Spring Framework Escalation via Session Fixation in WebFlux
CVSS 4.2
CVE-2026-11335
MEDIUM
tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation
CVSS 6.3
CVE-2026-33384
MEDIUM
Session Fixation in QuickCMS
CVE-2026-48545
MEDIUM
Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
CVSS 6.8
CVE-2026-43827
MEDIUM
Apache Shiro: Session fixation: new session is not created after login by default
CVSS 6.5
CVE-2026-45773
MEDIUM
Turborepo: Login callback CSRF/session fixation
CVSS 6.5
CVE-2026-41613
HIGH
Visual Studio Code Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-30808
HIGH
Pandora FMS 777-800 - Session Fixation via Crafted Session ID
CVSS 8.1
CVE-2026-40010
CRITICAL
Apache Wicket: possible session fixation using AuthenticatedWebSession
CVSS 9.1
CVE-2026-34454
LOW
OAuth2 Proxy: Session cookie not cleared when rendering sign-in page
CVSS 3.5
CVE-2026-31940
HIGH
Session Fixation in Chamilo LMS
CVSS 7.5
CVE-2026-33946
MEDIUM
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
CVSS 5.9
CVE-2026-33757
CRITICAL
OpenBao lacks user confirmation for OIDC direct callback mode
CVSS 9.6
CVE-2026-25101
CRITICAL
Session Fixation in Bludit
CVSS 9.8
CVE-2026-33492
HIGH
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
CVSS 7.3
CVE-2026-30224
MEDIUM
olivetin < 3000.11.1 - Session Fixation via Incomplete Logout
CVSS 5.4
CVE-2026-24352
CRITICAL
PluXml CMS 5.8.21/5.9.0-rc7 - Session Fixation
CVSS 9.8
CVE-2026-24894
HIGH
FrankenPHP <1.11.2 - Info Disclosure
CVSS 7.5
CVE-2026-2177
HIGH
SourceCodester Prison Management System 1.0 - Session Fixation
CVSS 7.3
CVE-2026-23796
CRITICAL
Quick.Cart <6.7 - Session Hijacking
CVSS 9.8
CVE-2026-23624
MEDIUM
GLPI <10.0.23-11.0.5 - Info Disclosure
CVSS 4.3
CVE-2026-22082
HIGH
Tenda Wireless Router - Auth Bypass
CVE-2025-67446
CRITICAL
Neterbit NW-431F Router <= 20241014-IR03 - Unauthenticated Authentication Bypass via Weak Cookie Value
CVSS 9.8
CVE-2025-65415
MEDIUM
docuFORM Managed Print Service Client 11.11c - Session Fixation
CVSS 5.4
CVE-2025-46605
MEDIUM
Dell PowerProtect Data Domain 8.4-8.5 - Session Fixation
CVSS 6.2
Details
Vulnerabilities
404