CWE-209
Generation of Error Message Containing Sensitive Information
Description
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7
CVEs mapped to this weakness (631)
page 15 of 32| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38010 | Med | 0.34 | 5.3 | 0.00 | Feb 4, 2026 | IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system. | ||
| CVE-2025-52023 | Med | 0.34 | 5.3 | 0.00 | Jan 23, 2026 | A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests… | ||
| CVE-2025-52022 | Med | 0.34 | 5.3 | 0.00 | Jan 23, 2026 | A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST… | ||
| CVE-2026-1175 | Med | 0.34 | 5.3 | 0.00 | Jan 19, 2026 | A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Directive Handler. Such manipulation leads to information exposure through error message. The attack may be performed from remote.… | ||
| CVE-2025-15526 | Med | 0.34 | 5.3 | 0.00 | Jan 16, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This… | ||
| CVE-2025-9122 | Med | 0.34 | 5.3 | 0.00 | Dec 15, 2025 | Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet. | ||
| CVE-2025-61959 | Med | 0.34 | 5.3 | 0.00 | Oct 29, 2025 | Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors… | ||
| CVE-2025-12365 | Med | 0.34 | 5.3 | 0.00 | Oct 27, 2025 | Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | ||
| CVE-2025-62397 | Med | 0.34 | 5.3 | 0.00 | Oct 23, 2025 | The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance. | ||
| CVE-2025-54291 | Med | 0.34 | 5.3 | 0.00 | Oct 2, 2025 | Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses. | ||
| CVE-2025-9229 | Med | 0.34 | 5.3 | 0.00 | Aug 20, 2025 | Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages. | ||
| CVE-2025-52619 | Med | 0.34 | 5.3 | 0.00 | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform. | ||
| CVE-2024-37524 | Med | 0.34 | 5.3 | 0.00 | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | ||
| CVE-2025-41441 | Med | 0.34 | 5.3 | 0.00 | May 26, 2025 | Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature. | ||
| CVE-2025-20150 | Med | 0.34 | 5.3 | 0.01 | Apr 16, 2025 | A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication… | ||
| CVE-2025-2239 | Med | 0.34 | 5.3 | 0.00 | Mar 12, 2025 | Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23. | ||
| CVE-2025-20002 | Med | 0.34 | 5.3 | 0.00 | Mar 5, 2025 | After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure | ||
| CVE-2024-13537 | Med | 0.34 | 5.3 | 0.00 | Feb 21, 2025 | The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file with error display enabled. This makes it possible for unauthenticated attackers… | ||
| CVE-2024-13540 | Med | 0.34 | 5.3 | 0.00 | Feb 18, 2025 | The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being publicly accessible and generating a… | ||
| CVE-2024-13538 | Med | 0.34 | 5.3 | 0.01 | Feb 18, 2025 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This… |
- risk 0.34cvss 5.3epss 0.00
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.
- risk 0.34cvss 5.3epss 0.00
A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests…
- risk 0.34cvss 5.3epss 0.00
A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Directive Handler. Such manipulation leads to information exposure through error message. The attack may be performed from remote.…
- risk 0.34cvss 5.3epss 0.00
The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This…
- risk 0.34cvss 5.3epss 0.00
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
- risk 0.34cvss 5.3epss 0.00
Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors…
- risk 0.34cvss 5.3epss 0.00
Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- risk 0.34cvss 5.3epss 0.00
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
- risk 0.34cvss 5.3epss 0.00
Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.
- risk 0.34cvss 5.3epss 0.00
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.
- risk 0.34cvss 5.3epss 0.00
HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, error messages disclose sensitive version information about the underlying platform.
- risk 0.34cvss 5.3epss 0.00
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
- risk 0.34cvss 5.3epss 0.00
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
- risk 0.34cvss 5.3epss 0.01
A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication…
- risk 0.34cvss 5.3epss 0.00
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.
- risk 0.34cvss 5.3epss 0.00
After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure
- risk 0.34cvss 5.3epss 0.00
The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible composer-setup.php file with error display enabled. This makes it possible for unauthenticated attackers…
- risk 0.34cvss 5.3epss 0.00
The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This is due the /inc/bycwooodt_get_all_orders.php file being publicly accessible and generating a…
- risk 0.34cvss 5.3epss 0.01
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.0. This is due the /vendor/cocur/slugify/bin/generate-default.php file being directly accessible and triggering an error. This…