VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (217)

page 1 of 11
  • CVE-2022-0482CriMar 9, 2022
    risk 0.59cvss 9.1epss 0.44

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

  • CVE-2023-36052HigNov 14, 2023
    risk 0.58cvss 8.6epss 0.21

    Azure CLI REST Command Information Disclosure Vulnerability

  • CVE-2025-13008HigDec 19, 2025
    risk 0.56cvss —epss 0.00

    An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.

  • CVE-2025-66172HigMay 8, 2026
    risk 0.53cvss 8.1epss 0.01

    The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can restore a volume from any other…

  • CVE-2025-11959HigNov 11, 2025
    risk 0.53cvss 8.1epss 0.00

    Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information System allows Footprinting, Functionality Misuse. This issue…

  • CVE-2024-26192HigFeb 23, 2024
    risk 0.53cvss 8.2epss 0.02

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2023-36018HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.02

    Visual Studio Code Jupyter Extension Spoofing Vulnerability

  • CVE-2025-53625HigJul 10, 2025
    risk 0.50cvss —epss 0.00

    The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppression, or the hideuser block flag. The…

  • CVE-2022-2921HigAug 21, 2022
    risk 0.50cvss 8.8epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update…

  • CVE-2026-86904HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.

  • CVE-2026-84606HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.

  • CVE-2026-28938HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.

  • CVE-2026-74966HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-48615HigJun 26, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error…

  • CVE-2019-25762HigJun 19, 2026
    risk 0.49cvss 7.5epss 0.01

    Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=c…

  • CVE-2026-26237HigJun 10, 2026
    risk 0.49cvss 7.5epss 0.00

    A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and…

  • CVE-2026-28906HigMay 11, 2026
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.

  • CVE-2025-15623HigApr 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in…

  • CVE-2020-37173HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.01

    AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by…

  • CVE-2026-24735HigFeb 4, 2026
    risk 0.49cvss 7.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to…