VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 7 of 43
  • CVE-2021-27140HigFeb 10, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.

  • CVE-2020-24577HigJan 8, 2021
    risk 0.50cvss 7.5epss 0.19

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the…

  • CVE-2020-27986HigOct 28, 2020
    risk 0.50cvss 7.5epss 0.16

    SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

  • CVE-2009-5068HigJan 15, 2020
    risk 0.50cvss 7.2epss 0.02

    There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary…

  • CVE-2019-10449HigOct 16, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10440HigOct 16, 2019
    risk 0.50cvss 8.8epss 0.01

    Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10348HigJul 11, 2019
    risk 0.50cvss 8.8epss 0.02

    Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-3606HigMar 26, 2019
    risk 0.50cvss 7.7epss 0.00

    Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI…

  • CVE-2026-13380HigJul 20, 2026
    risk 0.49cvss 7.5epss 0.00

    VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is…

  • CVE-2026-56270HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by…

  • CVE-2026-6332HigMay 14, 2026
    risk 0.49cvss 7.5epss 0.00

    CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for…

  • CVE-2024-55027HigMar 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

  • CVE-2026-27520HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access…

  • CVE-2025-12774HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries in the SANnav support save file. An attacker with access to Brocade SANnav supportsave file, could open the file and then obtain sensitive information such…

  • CVE-2026-22240HigJan 14, 2026
    risk 0.49cvss 7.5epss 0.03

    The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to…

  • CVE-2019-25279HigJan 8, 2026
    risk 0.49cvss 7.5epss 0.00

    FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in…

  • CVE-2020-36887HigDec 10, 2025
    risk 0.49cvss 7.5epss 0.00

    SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system…

  • CVE-2025-65320HigDec 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory during an activation attempt.

  • CVE-2025-65278HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.

  • CVE-2025-25613HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were…