VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 42 of 43
  • CVE-2019-14825LowNov 25, 2019
    risk 0.11cvss 2.7epss 0.01

    A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged…

  • CVE-2025-7215LowJul 9, 2025
    risk 0.10cvss 1.6epss 0.00

    A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage of sensitive information. It is possible…

  • CVE-2024-36119LowMay 30, 2024
    risk 0.05cvss 1.8epss 0.00

    Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the…

  • CVE-2013-5676Dec 13, 2013
    risk 0.03cvss epss 0.05

    The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

  • CVE-2026-15721CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2026-59327MedJul 30, 2026
    risk 0.00cvss 4.4epss 0.00

    Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace…

  • CVE-2026-16802MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.00

    Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

  • CVE-2024-58023HigJul 23, 2026
    risk 0.00cvss 8.4epss 0.00

    Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

  • CVE-2026-65599MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only for a key identifier). Because JWT headers…

  • CVE-2026-16213LowJul 19, 2026
    risk 0.00cvss 3.3epss 0.00

    A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in…

  • CVE-2026-38571MedJun 26, 2026
    risk 0.00cvss 4.6epss 0.00

    Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and…

  • CVE-2025-54422MedJul 29, 2025
    risk 0.00cvss 5.5epss 0.00

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via…

  • CVE-2024-52525LowNov 15, 2024
    risk 0.00cvss 1.8epss 0.00

    Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process…

  • CVE-2024-43429MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.

  • CVE-2024-7783HigOct 29, 2024
    risk 0.00cvss 7.5epss 0.00

    mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This…

  • CVE-2023-48305MedNov 21, 2023
    risk 0.00cvss 4.2epss 0.00

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, when the log level was set to debug, the user_ldap app logged…

  • CVE-2023-45151MedOct 16, 2023
    risk 0.00cvss 6.5epss 0.00

    Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has been addressed and users are recommended…

  • CVE-2023-37468MedJul 13, 2023
    risk 0.00cvss 6.0epss 0.00

    Feedbacksystem is a personalized feedback system for students using artificial intelligence. Passwords of users using LDAP login are stored in clear text in the database. The LDAP users password is passed unencrypted in the LoginController.scala and stored in the database when…

  • CVE-2023-23944LowFeb 6, 2023
    risk 0.00cvss 2.0epss 0.00

    Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were stored in cleartext in the database during the duration of OAuth2 setup procedure. Any attacker or malicious user with access to the database would have access…

  • CVE-2022-46155HigNov 29, 2022
    risk 0.00cvss 7.6epss 0.00

    Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script in its source package. When the build script is run, it would bundle environment variables into the build target of a transpiled bundle. Specifically, the…