VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (279)

page 3 of 14
  • CVE-2026-40430HigJul 23, 2026
    risk 0.49cvss 7.5epss 0.00

    Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

  • CVE-2018-25396HigMay 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username…

  • CVE-2025-15624HigApr 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in…

  • CVE-2026-35556HigApr 9, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

  • CVE-2026-33216HigMar 25, 2026
    risk 0.49cvss 8.6epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and…

  • CVE-2025-9982HigNov 14, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially…

  • CVE-2024-41336HigFeb 27, 2025
    risk 0.49cvss 7.5epss 0.00

    Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor…

  • CVE-2025-21111HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

  • CVE-2025-21102HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

  • CVE-2023-6518HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.

  • CVE-2023-39452HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

  • CVE-2023-35067HigJul 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.

  • CVE-2023-0457HigMar 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP…

  • CVE-2022-43958HigNov 8, 2022
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). User credentials are stored in plaintext in the database without any hashing mechanism. This could allow an attacker to gain access to credentials and…

  • CVE-2022-31044HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any…

  • CVE-2022-22557HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.00

    PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker…

  • CVE-2021-32978HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior…

  • CVE-2020-8183HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.02

    A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

  • CVE-2020-10609HigJul 27, 2020
    risk 0.49cvss 7.5epss 0.02

    Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by someone with access to the device.

  • CVE-2019-10434HigOct 1, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.