Cyber Posture

CWE · MITRE source

CWE-804Guessable CAPTCHA

Abstraction: Base · CVEs in our corpus: 14

The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.

An automated attacker could bypass the intended protection of the CAPTCHA challenge and perform actions at a higher frequency than humanly possible, such as launching spam attacks. There can be several different causes of a guessable CAPTCHA:

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-409161.89.10.00282025-06-16
CVE-2025-508501.78.60.00092025-07-31
CVE-2022-18011.57.50.00242022-06-20
CVE-2022-40361.15.30.00092022-11-29
CVE-2023-69631.15.30.00122024-02-05
CVE-2024-305401.15.30.00162024-05-17
CVE-2024-312951.15.30.00092024-05-17
CVE-2025-12621.15.30.00122025-02-25
CVE-2025-85461.15.30.00102025-08-05
CVE-2026-274111.15.30.00042026-03-05
CVE-2025-701291.15.30.00052026-03-10
CVE-2026-409351.15.30.00042026-04-21
CVE-2025-320360.94.20.00172025-04-08
CVE-2025-104230.73.70.00052025-09-15