VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 39 of 43
  • CVE-2025-49728MedSep 16, 2025
    risk 0.26cvss 4.0epss 0.00

    Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2023-48707MedNov 24, 2023
    risk 0.26cvss 5.0epss 0.00

    CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the…

  • CVE-2022-27549MedJul 6, 2022
    risk 0.26cvss 4.0epss 0.00

    HCL Launch may store certain data for recurring activities in a plain text format.

  • CVE-2023-22894MedApr 19, 2023
    risk 0.25cvss 4.9epss 0.02

    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super…

  • CVE-2018-10871LowJul 18, 2018
    risk 0.25cvss 3.8epss 0.01

    389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker…

  • CVE-2026-50267MedJun 17, 2026
    risk 0.24cvss 4.7epss 0.00

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials,…

  • CVE-2026-8026LowMay 6, 2026
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in information disclosure. The attack can…

  • CVE-2025-8528LowAug 4, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack…

  • CVE-2023-5359LowSep 25, 2024
    risk 0.24cvss 3.7epss 0.01

    The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3…

  • CVE-2023-4392LowAug 17, 2023
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation leads to cleartext storage of sensitive information. The attack may be launched…

  • CVE-2022-29832LowNov 25, 2022
    risk 0.24cvss 3.7epss 0.01

    Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote unauthenticated attacker to disclose sensitive information.…

  • CVE-2020-36473LowAug 14, 2021
    risk 0.24cvss 3.7epss 0.01

    UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.

  • CVE-2024-51993LowNov 7, 2024
    risk 0.22cvss 3.4epss 0.00

    Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured Users. This issue has been addressed in version 3.2.0 and all users are advised to upgrade. Users unable to upgrade are advised…

  • CVE-2023-46294LowMay 1, 2024
    risk 0.22cvss 3.4epss 0.00

    An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This utility requires root permissions to execute.

  • CVE-2018-5559LowNov 28, 2018
    risk 0.22cvss 3.4epss 0.01

    In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue…

  • CVE-2026-45362LowMay 12, 2026
    risk 0.21cvss 3.2epss 0.00

    Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

  • CVE-2026-6598MedApr 20, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Creation Endpoint. Such manipulation of the…

  • CVE-2025-33081LowFeb 3, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2025-67638MedDec 10, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-67637MedDec 10, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.