CWE-384

Session Fixation

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

416 vulnerabilities with CWE-384
CVE-2025-37159 MEDIUM
ArubaOS-CX 10.10.0000-10.10.1169 - Authenticated Session Fixation
CVSS 5.8
CVE-2025-64100 MEDIUM
CKAN <2.10.9, <2.11.4 - Info Disclosure
CVSS 6.1
CVE-2025-12390 MEDIUM
Keycloak < 26.0.0 - Session Fixation via Incomplete Session Cleanup
CVSS 6.0
CVE-2025-56746 LOW
Creativeitem Academy LMS <=5.13 - Info Disclosure
CVSS 2.2
CVE-2025-10228 HIGH
Rolantis Information Technologies Agentis <4.44 - Info Disclosure
CVSS 8.8
CVE-2025-59841 CRITICAL
flagforge 2.2.0-2.3.0 - Insufficient Session Expiration
CVSS 9.8
CVE-2025-54761 HIGH
PPress 0.0.9 - Privilege Escalation
CVSS 8.0
CVE-2025-4644 MEDIUM
Payload CMS < 3.44.0 - Session Fixation via SQLite Adapter Identifier Reuse
CVE-2025-55668 MEDIUM
Apache Tomcat <11.0.7, <10.1.41, <9.0.105 - Session Fixation
CVSS 6.5
CVE-2025-8517 MEDIUM
givanz Vvveb <1.0.6.1 - Info Disclosure
CVSS 6.3
CVE-2025-53102 CRITICAL
Discourse <3.4.7-3.5.0.beta.8 - Info Disclosure
CVSS 9.8
CVE-2025-0253 LOW
HCL IntelliOps Event Management - Session Fixation via Insecure Cookie Attributes
CVSS 2.0
CVE-2025-0251 LOW
HCL IntelliOps Event Management - Concurrent Session Vulnerability
CVSS 2.6
CVE-2025-36117 MEDIUM
IBM Db2 Mirror for i 7.4-7.6 - Privilege Escalation
CVSS 6.3
CVE-2025-51471 MEDIUM
Ollama 0.6.7 - Cross-Domain Token Exposure via WWW-Authenticate Header Realm
CVSS 6.9
CVE-2025-52689 CRITICAL
Alcatel-Lucent OmniAccess Stellar Products <= 5.0.2 GA - Unauthenticated Session Fixation via Spoofed Login Request
CVSS 9.8
CVE-2025-53895 HIGH
ZITADEL <4.0.0-rc.2, 3.3.2, 2.71.13, 2.70.14 - Privilege Escalation
CVSS 8.8
CVE-2025-53021 MEDIUM
Moodle 3.0.0-3.11.18 - Unauthenticated Session Fixation via sesskey Parameter
CVSS 4.2
CVE-2025-46815 HIGH
ZITADEL < 2.70.10 and 2.71.x < 2.71.9 and 3.0.0-rc.1-3.0.0 - Session Hijacking via IdP Intent Reuse
CVSS 8.0
CVE-2025-45953 CRITICAL
PHPGurukul Hostel Mgt Sys 2.1 - Session Hijacking
CVSS 9.1
CVE-2025-45949 CRITICAL
PHPGurukul User Registration & Login and User Management System V3.3 - Session Hijacking
CVSS 9.8
CVE-2025-42602 HIGH
Meon KYC solutions - Session Fixation via API Token Handling
CVE-2025-28242 CRITICAL
DAEnetIP4 METO v1.25 - Session Hijacking
CVSS 9.8
CVE-2025-28238 CRITICAL
Elber REBLE310 Firmware <5.5.1.R - Session Hijacking
CVSS 9.8
CVE-2025-0126 HIGH
PAN-OS 10.1.0-10.1.14-h11, 10.2.0-10.2.10-h6, 11.0.0-11.0.6, 11.1.0-11.1.5, 11.2.0-11.2.3 SAML Session Fixation
Details
Vulnerabilities 416