VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (286)

page 15 of 15
  • CVE-2026-14867MedJul 7, 2026
    risk 0.00cvss 5.5epss 0.00

    Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.  Active Directory accounts are not affected by this vulnerability.

  • CVE-2025-56527HigNov 18, 2025
    risk 0.00cvss 7.5epss 0.00

    Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

  • CVE-2022-0555HigJun 3, 2024
    risk 0.00cvss 8.4epss 0.00

    Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

  • CVE-2024-26133MedFeb 21, 2024
    risk 0.00cvss 5.5epss 0.01

    EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom…

  • CVE-2022-45392MedNov 15, 2022
    risk 0.00cvss 6.5epss 0.01

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-3287MedSep 28, 2022
    risk 0.00cvss 6.5epss 0.01

    When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.