VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (217)

page 11 of 11
  • CVE-2026-62328HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI…

  • CVE-2026-58297HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58296HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57960MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET…

  • CVE-2026-56124HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.01

    phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and…

  • CVE-2025-66510MedDec 5, 2025
    risk 0.00cvss 4.5epss 0.00

    Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names,…

  • CVE-2025-66027MedNov 29, 2025
    risk 0.00cvss 6.5epss 0.00

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy…

  • CVE-2025-59843MedSep 26, 2025
    risk 0.00cvss 5.3epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email…

  • CVE-2025-53374MedJul 7, 2025
    risk 0.00cvss 4.3epss 0.00

    Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly…

  • CVE-2024-53258MedNov 25, 2024
    risk 0.00cvss 5.3epss 0.00

    Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for…

  • CVE-2023-25819MedMar 4, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `tests-passed` version of…

  • CVE-2023-26041LowFeb 27, 2023
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk…

  • CVE-2022-46168LowJan 5, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users inside the group SMTP topic.…

  • CVE-2022-41971MedDec 1, 2022
    risk 0.00cvss 4.8epss 0.01

    Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call…

  • CVE-2022-0852MedAug 29, 2022
    risk 0.00cvss 5.5epss 0.00

    There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact…

  • CVE-2022-35932LowAug 12, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk…

  • CVE-2022-24890LowMay 17, 2022
    risk 0.00cvss 2.4epss 0.01

    Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5…