VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (203)

page 3 of 11
  • CVE-2022-36091HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.01

    XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 and 14.2. This includes private personal…

  • CVE-2021-21823HigAug 20, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can lead to the disclosure of sensitive information.

  • CVE-2023-50719HigDec 15, 2023
    risk 0.48cvss 7.5epss 0.84

    XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user…

  • CVE-2026-49344HigJun 19, 2026
    risk 0.46cvss epss 0.00

    Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts a JSON DSL (`from` / `select` / `filters` / `traverse` / `output`), translates it into an Eloquent…

  • CVE-2026-35675HigMay 28, 2026
    risk 0.46cvss 8.2epss 0.00

    phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain…

  • CVE-2025-13477HigMay 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted…

  • CVE-2025-14317HigJan 14, 2026
    risk 0.46cvss epss 0.00

    In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and…

  • CVE-2024-30056HigMay 25, 2024
    risk 0.46cvss 7.1epss 0.02

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2025-62362MedOct 13, 2025
    risk 0.45cvss epss 0.00

    gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network…

  • CVE-2024-37136MedSep 3, 2024
    risk 0.44cvss 6.8epss 0.00

    Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information exposure.

  • CVE-2025-66035HigNov 26, 2025
    risk 0.43cvss epss 0.01

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability…

  • CVE-2024-42347HigAug 6, 2024
    risk 0.43cvss 7.7epss 0.00

    matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages…

  • CVE-2026-48048HigAug 10, 2026
    risk 0.42cvss 7.5epss 0.00

    XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is…

  • CVE-2026-24078MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

  • CVE-2025-66171MedMay 8, 2026
    risk 0.42cvss 6.5epss 0.01

    The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs can create new VMs using backups of any…

  • CVE-2026-7382MedApr 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

  • CVE-2026-34226HigMar 27, 2026
    risk 0.42cvss 7.5epss 0.00

    Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(..., { credentials: "include" })` is used.…

  • CVE-2025-41685MedAug 19, 2025
    risk 0.42cvss 6.5epss 0.00

    A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.

  • CVE-2025-26816MedMar 19, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.

  • CVE-2024-42494MedDec 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services