CVEs classified under CWE-804, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (12)
CVE-2024-23566 — CVSS 6.5 (medium): HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various…
CVE-2026-49953 — CVSS 6.5 (medium): Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to…
CVE-2026-40935 — CVSS 5.3 (medium): WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`)…
CVE-2025-70129 — CVSS 5.3 (medium): If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format…
CVE-2025-1262 — CVSS 5.3 (medium): The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it…
CVE-2024-31295 — CVSS 5.3 (medium): Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by…
CVE-2024-30540 — CVSS 5.3 (medium): Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through…
CVE-2023-6963 — CVSS 5.3 (medium): The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it…
CVE-2022-4036 — CVSS 5.3 (medium): The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to…
CVE-2024-23567 — CVSS 4.3 (medium): HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL…
CVE-2025-32036 — CVSS 4.2 (medium): DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to…