Falhas do tipo CWE-804

18 resultados

CAPTCHA adivinhável

Um CAPTCHA (teste para diferenciar humanos de bots) implementado com lógica fraca ou previsível, permitindo que um atacante adivinhe ou contorne a resposta sem resolver o desafio real. Isso anula a proteção contra força bruta e automatização de ataques, como roubo de conta ou spam.

Exemplo

Um site usa um CAPTCHA numérico com apenas 3 dígitos (0-999 combinações), ou o código válido persiste por muito tempo e pode ser reutilizado. Um atacante pode testar todas as variações em segundos ou simplesmente reenviar o mesmo código várias vezes.

Como mitigar

Use CAPTCHAs estabelecidos (reCAPTCHA, hCaptcha) em vez de implementar do zero. Se implementar, garanta variação suficiente (≥10⁶ combinações), expiração rápida (2-5 min), invalidação após falha e rate limiting rigoroso. Nunca confie unicamente no CAPTCHA para proteção crítica.

CVE-2022-1801Very Simple Contact Form < 11.6 - Captcha bypassEPSS 1.2%CVE-2023-6963MEDIUMGetwid – Gutenberg Blocks <= 2.0.4 - Captcha BypassEPSS 0.5%CVE-2024-30540MEDIUMWordPress VS Contact Form plugin <= 14.7 - Sum Captcha Bypass vulnerabilityEPSS 0.5%CVE-2025-8546MEDIUMatjiu pybbs Verification Code login CaptchaEPSS 0.5%CVE-2022-4036MEDIUMAppointment Hour Booking <= 1.3.72 - CAPTCHA BypassEPSS 0.4%CVE-2025-10423MEDIUMnewbee-mall kaptcha mallKaptcha CaptchaEPSS 0.4%CVE-2024-31295MEDIUMWordPress Captcha by BestWebSoft plugin <= 5.2.0 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2026-49953MEDIUMDiscuz! X5.0 CAPTCHA Bypass via Predictable Character SetEPSS 0.4%CVE-2025-40916CRITICALMojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha textEPSS 0.4%CVE-2025-1262MEDIUMAdvanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA BypassEPSS 0.3%CVE-2025-32036MEDIUMDNN allows the possibility of bypassing CaptchaEPSS 0.3%CVE-2025-70129MEDIUMIf the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format thatEPSS 0.3%CVE-2025-50850HIGHAn issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verificatiEPSS 0.2%CVE-2026-40935MEDIUMWWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on FailureEPSS 0.2%CVE-2026-13082MEDIUMGD::SecurityImage versions through 1.75 for Perl use rand to generate secretsEPSS 0.2%CVE-2026-27411MEDIUMWordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2024-23567MEDIUMHCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL paraEPSS 0.2%CVE-2024-23566MEDIUMHCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various securityEPSS 0.2%