CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
160 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-54125 — XWiki Platform: Password and email exposure in xml.vm fields
- CVE-2025-53625 — DynamicPageList3 exposes hidden/suppressed usernames
- CVE-2025-20060 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actor
- CVE-2024-47087 — Information Disclosure Vulnerability
- CVE-2024-47085 — Parameter Manipulation Vulnerability
- CVE-2025-13008 — Session Token Disclosure in M-Files Web
- CVE-2025-10450 — Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.
- CVE-2025-0683 — Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitor
- CVE-2025-15623 — Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
- CVE-2024-42347 — URL preview setting for a room is controllable by the homeserver in matrix-react-sdk
- CVE-2024-10267 — Information Disclosure in transformeroptimus/superagi
- CVE-2026-62328 — 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
- CVE-2026-56124 — phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
- CVE-2019-25762 — Joomla! Component JoomProject 1.1.3.2 Information Disclosure
- CVE-2025-66027 — Rallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy Settings
- CVE-2025-54124 — XWiki Platform: Any user with editing rights can access password properties through Database List Properties
- CVE-2025-24355 — Updatecli may expose Maven credentials in console output
- CVE-2025-14317 — User Enumeration in Crazy Bubble Tea mobile application
- CVE-2024-53258 — download_all_submissions allows student to download another student's submissions in Autolab
- CVE-2024-42494 — Ruijie Reyee OS Exposure of Private Personal Information to an Unauthorized Actor
Recently published
- CVE-2026-21827 — HCL Connections is vulnerable to an information disclosure vulnerability
- CVE-2026-53497 — CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-48048 — XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
- CVE-2026-24078 — Exposure of Private Personal Information to an Unauthorized Actor in Data Modem
- CVE-2026-55496 — Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate
- CVE-2026-62328 — 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
- CVE-2026-57960 — Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
- CVE-2026-56124 — phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
- CVE-2026-48615 — A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. Wh
- CVE-2026-54264 — Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
- CVE-2026-49344 — Mercator has a Personal Identifiable Information Leak from Query Executor feature
- CVE-2019-25762 — Joomla! Component JoomProject 1.1.3.2 Information Disclosure
- CVE-2026-26237 — QuMagie
- CVE-2026-25699 — Apache Answer: Authorization Bypass in Timeline API
- CVE-2020-25900 — HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or
- CVE-2026-8990 — Authentication Bypass in Kidsview
- CVE-2025-13477 — OTP Bypass in Digital Operation Services' WifiBurada
- CVE-2025-66172 — Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
- CVE-2025-66171 — Apache CloudStack: Any user can create a new VM from backups they should not have access to