VYPR

CWE-540

Inclusion of Sensitive Information in Source Code

BaseIncomplete

Description

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

There are situations where it is critical to remove source code from an area or server. For example, obtaining Perl source code on a system allows an attacker to understand the logic of the script and extract extremely useful information such as code bugs or logins and passwords.

Hierarchy (View 1000)

CVEs mapped to this weakness (31)

page 1 of 2
  • CVE-2025-26013HigFeb 21, 2025
    risk 0.53cvss 8.2epss 0.00

    An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.

  • CVE-2025-23215CriJan 31, 2025
    risk 0.53cvss epss 0.00

    PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must…

  • CVE-2023-39250HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could…

  • CVE-2021-28805HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.3 build 20210505 on…

  • CVE-2026-4155HigApr 11, 2026
    risk 0.49cvss 7.5epss 0.01

    ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not…

  • CVE-2025-49182HigJun 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

  • CVE-2024-38647HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core…

  • CVE-2024-1272HigJun 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedded Sensitive Data. This issue affects Cockpit Software: before v0.251.1.

  • CVE-2024-38327MedJul 10, 2025
    risk 0.44cvss 6.8epss 0.00

    IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which could assist an attacker to read and debug JavaScript used in the application's API.

  • CVE-2026-45728HigMay 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or…

  • CVE-2026-35383MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to…

  • CVE-2021-34638MedAug 5, 2021
    risk 0.42cvss 6.5epss 0.01

    Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing…

  • CVE-2024-2265MedMar 7, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack…

  • CVE-2023-30802MedOct 10, 2023
    risk 0.35cvss 5.3epss 0.01

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.

  • CVE-2023-23448MedMay 15, 2023
    risk 0.35cvss 5.3epss 0.01

    Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

  • CVE-2026-16581MedJul 28, 2026
    risk 0.34cvss 5.3epss 0.00

    In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.

  • CVE-2025-0923MedJun 11, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.

  • CVE-2024-35144MedJan 25, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.

  • CVE-2021-34757MedOct 6, 2021
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the…

  • CVE-2021-34744MedOct 6, 2021
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the…