Skip to main content

CWE archive

CWE-804 CVEs

Programmatic archive

18 CVEs tagged with CWE-8041 Critical, 2 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2024-23567

Published Jul 17, 2026

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-23566

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated at…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13082

Published Jul 17, 2026

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an ar…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-49953

Published Jun 15, 2026

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting lim…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
24.1

CVE-2026-40935

Published Apr 21, 2026

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from the query string with no clampin…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-70129

Published Mar 10, 2026

If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for ar…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-27411

Published Mar 5, 2026

Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affects SiteGuard WP Plugin: from n/a through <= 1.7.9.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10423

Published Sep 15, 2025

A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The manipulation results in guessable captcha. The attack can…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8546

Published Aug 5, 2025

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50850

Published Jul 31, 2025

An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an at…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-40916

Published Jun 16, 2025

Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That version uses the built-in rand() function for generating t…

CVSS 9.1 · Critical

CVE-2025-32036

Published Apr 8, 2025

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least comp…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1262

Published Feb 25, 2025

The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-31295

Published May 17, 2024

Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through 5.2.0.

CVSS 5.3 · Medium

CVE-2024-30540

Published May 17, 2024

Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.

CVSS 5.3 · Medium

CVE-2023-6963

Published Feb 5, 2024

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4036

Published Nov 29, 2022

The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1