Weaknesses of type CWE-804

18 results

CAPTCHA Adivinhável

É quando um CAPTCHA (teste para distinguir humanos de bots) usa um desafio tão fácil de adivinhar ou quebrar que um atacante consegue passar sistematicamente sem resolver o desafio de verdade. Isso anula a proteção contra automação e força bruta, permitindo que bots explorem a aplicação.

Example

Um site usa CAPTCHA baseado em pergunta simples como 'Quanto é 2+2?' ou gera códigos numéricos curtos (3 dígitos) com baixa entropia. Um atacante escreve um script que tenta todas as combinações ou responde a pergunta facilmente, conseguindo registrar contas em massa ou fazer login por força bruta.

How to mitigate

Use CAPTCHAs robustos como reCAPTCHA v3 (Google) ou hCaptcha, que combinam múltiplos sinais de comportamento. Se precisar de desafio customizado, garanta entropia suficiente (mínimo 60 bits), implemente rate limiting severo, e adicione verificações de padrão de comportamento anormal (múltiplas tentativas em curto período).

CVE-2022-1801Very Simple Contact Form < 11.6 - Captcha bypassEPSS 1.2%CVE-2023-6963MEDIUMGetwid – Gutenberg Blocks <= 2.0.4 - Captcha BypassEPSS 0.5%CVE-2024-30540MEDIUMWordPress VS Contact Form plugin <= 14.7 - Sum Captcha Bypass vulnerabilityEPSS 0.5%CVE-2025-8546MEDIUMatjiu pybbs Verification Code login CaptchaEPSS 0.5%CVE-2022-4036MEDIUMAppointment Hour Booking <= 1.3.72 - CAPTCHA BypassEPSS 0.4%CVE-2025-10423MEDIUMnewbee-mall kaptcha mallKaptcha CaptchaEPSS 0.4%CVE-2024-31295MEDIUMWordPress Captcha by BestWebSoft plugin <= 5.2.0 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2026-49953MEDIUMDiscuz! X5.0 CAPTCHA Bypass via Predictable Character SetEPSS 0.4%CVE-2025-40916CRITICALMojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha textEPSS 0.4%CVE-2025-1262MEDIUMAdvanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA BypassEPSS 0.3%CVE-2025-32036MEDIUMDNN allows the possibility of bypassing CaptchaEPSS 0.3%CVE-2025-70129MEDIUMIf the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format thatEPSS 0.3%CVE-2025-50850HIGHAn issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verificatiEPSS 0.2%CVE-2026-40935MEDIUMWWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on FailureEPSS 0.2%CVE-2026-13082MEDIUMGD::SecurityImage versions through 1.75 for Perl use rand to generate secretsEPSS 0.2%CVE-2026-27411MEDIUMWordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2024-23567MEDIUMHCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL paraEPSS 0.2%CVE-2024-23566MEDIUMHCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various securityEPSS 0.2%