CWE-312: Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
331 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-22896 — mySCADA myPRO Manager Cleartext Storage of Sensitive Information
- CVE-2026-22240 — Plaintext Passwords Vulnerability in BLUVOYIX
- CVE-2026-33026 — nginx-ui Backup Restore Allows Tampering with Encrypted Backups
- CVE-2025-7426 — MINOVA TTA Information Disclosure and Credential Exposure
- CVE-2025-34206 — Vasion Print (formerly PrinterLogic) Insecure Shared Storage Permissions
- CVE-2025-23215 — PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
- CVE-2026-33867 — AVideo has Plaintext Video Password Storage
- CVE-2026-25751 — FUXA Unauthenticated Exposure of Plaintext Database Credentials
- CVE-2025-14377 — Verve Asset Manager – Plaintext Storage Vulnerabilities
- CVE-2026-34833 — Bulwark Webmail: Information Exposure: password returned in /api/auth/session
- CVE-2025-34200 — Vasion Print (formerly PrinterLogic) Network Account Password Stored in Cleartext
- CVE-2025-12772 — Plaintext Switch admin login password is seen in Brocade SANnav support save
- CVE-2025-34216 — Vasion Print (formerly PrinterLogic) RCE and Password Leaks via API
- CVE-2025-3395 — Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB A
- CVE-2024-53979 — Ansible collection "ibm.ibm_zhmc" has passwords in clear text in log file and in output of some modules when specified as input
- CVE-2024-53865 — Python package "zhmcclient" has passwords in clear text in its HMC and API logs
- CVE-2024-38877 — A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont
- CVE-2026-43992 — JunoClaw: MCP write tools exposed raw BIP-39 mnemonic as a tool-call parameter
- CVE-2026-15721 — Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources
- CVE-2025-14815 — Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64
Recently published
- CVE-2026-80058 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-86280 — SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage
- CVE-2026-53603 — nebula-mesh: Operator session tokens stored in plaintext in the database
- CVE-2026-83551 — Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline path
- CVE-2026-77975 — Ebyte NA111-M Cleartext Storage of Sensitive Information
- CVE-2026-82699 — sambitraj Student Management System Password aca.sql cleartext storage
- CVE-2026-82640 — browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage
- CVE-2026-77970 — Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
- CVE-2026-75847 — Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
- CVE-2026-81683 — openssl_encrypt before 1.4.9 Plaintext Private Key Storage
- CVE-2026-59657 — Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
- CVE-2026-76405 — Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app
- CVE-2026-76386 — Information Disclosure through Action Parameters in Zoom app for Splunk SOAR
- CVE-2026-76385 — Information Disclosure through Action Parameters in Venafi app for Splunk SOAR
- CVE-2026-76384 — Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOAR
- CVE-2026-76383 — Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR
- CVE-2026-76382 — Information Disclosure through Action Parameters in Phantom app for Splunk SOAR
- CVE-2026-76381 — Information Disclosure through Action Parameters in MS Graph for Active Directory app for Splunk SOAR
- CVE-2026-76380 — Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOAR
- CVE-2026-76379 — Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOAR
More specific weaknesses
- CWE-313 — Cleartext Storage in a File or on Disk
- CWE-314 — Cleartext Storage in the Registry
- CWE-315 — Cleartext Storage of Sensitive Information in a Cookie
- CWE-316 — Cleartext Storage of Sensitive Information in Memory
- CWE-317 — Cleartext Storage of Sensitive Information in GUI
- CWE-318 — Cleartext Storage of Sensitive Information in Executable
- CWE-526 — Cleartext Storage of Sensitive Information in an Environment Variable