CVE-2022-27305High· 8.8▾ TwilightGibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
gibbon < 23.0.02Upgrade past the affected range:
gibbon 23.0.02Connected by shared product, vendor, weakness, or advisory.
CVE-2024-23679Critical· 9.8Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue
CVE-2026-95828Medium· 4.3A vulnerability was determined in Mstfakts College-Management-System
CVE-2026-79312Medium· 6.8webpy web.py 0.76 is vulnerable to Session Fixation
CVE-2026-61687High· 7.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
CVE-2026-82355Medium· 4.2When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…
CVE-2026-81181Low· 3.7SysReptor is a fully customizable pentest reporting platform