CWE-525: Use of Web Browser Cache Containing Sensitive Information
The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
30 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-48947 — NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
- CVE-2025-36364 — IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters.
- CVE-2026-13697 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
- CVE-2025-15554 — Admin Passwords Cached by Browsers in Truesec LAPSWebUI
- CVE-2026-41918 — A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio
- CVE-2025-62276 — The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver
- CVE-2026-41322 — @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed
- CVE-2026-24437 — Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
- CVE-2025-36082 — IBM OpenPages information disclosure
- CVE-2025-1348 — IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
- CVE-2025-1334 — IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure
- CVE-2024-22349 — IBM UrbanCode Velocity information disclosure
- CVE-2024-22343 — IBM TXSeries for Multiplatforms information disclosure
- CVE-2025-27525 — Information Exposure vulnerability in JP1/IT Desktop Management 2 - Smart Device Manager
- CVE-2025-52625 — HCL AION is susceptible to Cacheable SSL Page Found vulnerability
- CVE-2024-23571 — HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying
- CVE-2024-22333 — IBM Maximo Application Suite information disclosure
- CVE-2025-52659 — HCL AION is affected by a Cacheable HTTP Response vulnerability
- CVE-2025-13083 — Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
Recently published
- CVE-2026-13697 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
- CVE-2024-23571 — HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying
- CVE-2026-41918 — A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio
- CVE-2026-41322 — @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed
- CVE-2025-15554 — Admin Passwords Cached by Browsers in Truesec LAPSWebUI
- CVE-2025-36364 — IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters.
- CVE-2026-24437 — Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
- CVE-2025-52659 — HCL AION is affected by a Cacheable HTTP Response vulnerability
- CVE-2025-13083 — Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
- CVE-2025-62276 — The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver
- CVE-2025-52625 — HCL AION is susceptible to Cacheable SSL Page Found vulnerability
- CVE-2025-36082 — IBM OpenPages information disclosure
- CVE-2025-1348 — IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure
- CVE-2025-48947 — NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
- CVE-2025-1334 — IBM QRadar Suite Software and IBM Cloud Pak for Security information disclosure
- CVE-2025-27525 — Information Exposure vulnerability in JP1/IT Desktop Management 2 - Smart Device Manager
- CVE-2024-22349 — IBM UrbanCode Velocity information disclosure
- CVE-2024-22333 — IBM Maximo Application Suite information disclosure
- CVE-2024-22343 — IBM TXSeries for Multiplatforms information disclosure