CWE-384: Session Fixation

low-risk

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Abstraction: Compound

Common Consequences

Access Control Gain Privileges or Assume Identity

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2018-18925 9.8 93.6%
CVE-2022-31798 6.1 86.6%
CVE-2017-14263 8.1 24.4%
CVE-2017-12965 9.8 22.2%
CVE-2024-50339 5.3 21.5%
CVE-2015-4594 9.8 12.3%
CVE-2021-36394 9.8 11.6%
CVE-2019-12258 7.5 11.6%
CVE-2025-28242 9.8 11.5%
CVE-2019-18418 9.8 10.6%
3
/ 100
low-risk
Active Threat 3/50 · Minimal
Exploit Availability 0/50 · Minimal