VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (217)

page 10 of 11
  • CVE-2025-43301LowSep 15, 2025
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access contact info related to notifications in Notification Center.

  • CVE-2024-13228MedMar 11, 2025
    risk 0.21cvss 4.3epss 0.00

    The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above,…

  • CVE-2024-13217MedFeb 27, 2025
    risk 0.21cvss 4.3epss 0.00

    The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2024-13215MedJan 15, 2025
    risk 0.21cvss 4.3epss 0.01

    The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with…

  • CVE-2024-23211LowJan 23, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may be visible in Settings.

  • CVE-2023-42830LowJan 10, 2024
    risk 0.21cvss 3.3epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.

  • CVE-2026-21827LowAug 31, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

  • CVE-2026-0102LowFeb 17, 2026
    risk 0.20cvss 3.1epss 0.00

    Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.

  • CVE-2024-29888MedMar 27, 2024
    risk 0.20cvss 4.2epss 0.01

    Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect…

  • CVE-2025-51586LowSep 8, 2025
    risk 0.17cvss 3.7epss 0.01

    An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

  • CVE-2023-34085LowOct 25, 2023
    risk 0.17cvss 2.6epss 0.00

    When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

  • CVE-2023-29203LowApr 15, 2023
    risk 0.17cvss 3.7epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns…

  • CVE-2024-37533LowJul 24, 2024
    risk 0.16cvss 2.4epss 0.00

    IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.

  • CVE-2026-3911LowMar 11, 2026
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This…

  • CVE-2022-24719LowMar 1, 2022
    risk 0.10cvss 2.6epss 0.01

    Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that includes confidential headers such as…

  • CVE-2025-11598LowFeb 3, 2026
    risk 0.07cvss —epss 0.00

    In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the…

  • CVE-2025-5009LowOct 8, 2025
    risk 0.07cvss —epss 0.00

    In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable public link that contained the entire conversation history and not just the snippet.

  • CVE-2025-34441HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.

  • CVE-2026-56171HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.01

    Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-50657MedJul 14, 2026
    risk 0.00cvss 4.7epss 0.00

    Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.