CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

575 vulnerabilities with CWE-613
CVE-2026-1163 MEDIUM
Insufficient Session Expiration in parisneo/lollms
CVSS 4.1
CVE-2026-5376 MEDIUM
runZero Platform session timeout failure
CVSS 5.9
CVE-2026-35462 MEDIUM
Papra Does Not Reject Expired API Keys
CVSS 4.3
CVE-2026-34828 HIGH
listmonk: Active sessions remain valid after password reset and password change
CVSS 7.1
CVE-2026-34572 HIGH
CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
CVSS 8.8
CVE-2026-34570 HIGH
CI4MS: Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
CVSS 8.8
CVE-2026-34503 HIGH
OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation
CVSS 8.1
CVE-2026-26060 HIGH
Fleet: Password reset tokens remain valid after password change for 24 hours
CVSS 8.8
CVE-2026-34362 MEDIUM
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
CVSS 5.4
CVE-2026-29092 MEDIUM
Kiteworks Email Protection Gateway <9.2.1 - Session Expiration Bypass
CVSS 4.9
CVE-2026-33417 MEDIUM
Wallos: Password Reset Tokens Never Expire
CVSS 6.5
CVE-2026-32663 HIGH
IGL-Technologies eParking.fi Insufficient Session Expiration
CVSS 7.3
CVE-2026-27649 HIGH
CTEK Chargeportal Insufficient Session Expiration
CVSS 7.3
CVE-2026-32132 HIGH
ZITADEL <3.4.8/4.12.2 - Auth Bypass
CVSS 7.4
CVE-2026-30224 MEDIUM
olivetin < 3000.11.1 - Session Fixation via Incomplete Logout
CVSS 5.4
CVE-2026-27764 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-20748 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-24912 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-21622 CRITICAL
hexpm - Insufficient Session Expiration in Password Reset Token
CVSS 9.8
CVE-2026-28396 MEDIUM
NocoDB < 0.301.3 - Insufficient Session Expiration via Password Reset Flow
CVSS 6.5
CVE-2026-3401 LOW
SourceCodester Pharmacy Mgmt 1.0 - Auth Bypass
CVSS 3.1
CVE-2026-27647 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-26290 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-27652 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
CVE-2026-25778 HIGH
WebSocket Backend - Session Hijacking
CVSS 7.3
Details
Vulnerabilities 575