CWE-256: Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.
180 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-6561 — Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information
- CVE-2025-6560 — Sapido Wireless Router - Exposure of Sensitive Information
- CVE-2025-5893 — Honding Technology Smart Parking Management System - Exposure of Sensitive Information
- CVE-2025-34210 — Vasion Print (formerly PrinterLogic) Readable Cleartext Passwords
- CVE-2025-15113 — Ksenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload
- CVE-2025-2500 — A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an
- CVE-2025-7357 — Plaintext Storage of a Password in LITEON IC48A and IC80A EV Chargers
- CVE-2025-3758 — Exposure of Device Configuration without Authentication in WF2220
- CVE-2024-49370 — Change-Password via Portal-Profile sets PimcoreBackendUser password without hashing
- CVE-2024-43659 — Plaintext default credentials in firmware
- CVE-2024-5960 — Plaintext Storage of a Password in Eliz Software's Panel
- CVE-2024-36460 — Front-end audit log shows passwords in plaintext
- CVE-2024-43378 — calamares-nixos-extensions LUKS keyfile exposure regression on legacy BIOS systems
- CVE-2024-22432 — Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup dura
- CVE-2025-15624 — Plaintext Storage of a Password in Sparx Pro Cloud Server.
- CVE-2026-35556 — Plaintext storage of a password in OpenPLC_V3
- CVE-2025-21111 — Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privil
- CVE-2025-21102 — Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privil
- CVE-2024-27166 — Insecure permissions
- CVE-2024-10334 — Camera passwords stored in clear text
Recently published
- CVE-2026-19051 — Plaintext Storage of User Credentials in Menulux Software's Menulux Portal
- CVE-2026-15933 — Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)
- CVE-2021-38489 — HDD Password Stored In Plaintext
- CVE-2026-82453 — rust-iot-platform Cleartext Password Storage via User Model
- CVE-2026-55765 — CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod
- CVE-2026-55164 — Lemur: Plaintext password storage in Lemur user-update path
- CVE-2026-50641 — Plaintext password storage in Streamsoft Business Intelligence
- CVE-2026-41874 — Hard-coded admin credentials in Quick.Cart
- CVE-2026-61886 — Weintek cMT3092X Plaintext Storage of a Password
- CVE-2026-40430 — Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs
- CVE-2026-44187 — Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api key
- CVE-2026-46513 — Frogman: API tokens stored in plaintext
- CVE-2026-14867 — Insecure password storage in User directory
- CVE-2026-50268 — Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
- CVE-2024-39575 — update_disk_psu_baseline.sh requires password in plain text
- CVE-2024-45636 — IBM Security QRadar EDR Software has a vulnerability where user credentials may be stored in plain text, potentially exposing sensitive information.
- CVE-2018-25396 — Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
- CVE-2026-6500 — Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data.
- CVE-2025-36335 — Vulnerabilities found
- CVE-2026-6597 — langflow-ai langflow Flow Using API core.py has_api_terms credentials storage