CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
84 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-22433 — Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSetti
- CVE-2026-23838 — Tandoor Recipes module allows SQLite database to be externally accessible with the default settings
- CVE-2025-12059 — Improper Access Control in Logo Software's Logo j-Platform
- CVE-2024-51977 — Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
- CVE-2016-20024 — ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation
- CVE-2024-22045 — A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensit
- CVE-2026-49298 — Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
- CVE-2026-21672 — A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
- CVE-2025-68429 — Storybook manager bundle may expose environment variables during build
- CVE-2023-54346 — WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download
- CVE-2026-46617 — Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
- CVE-2026-27173 — Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
- CVE-2019-25706 — Across DR-810 ROM-0 Unauthenticated File Disclosure
- CVE-2025-46820 — phpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifact
- CVE-2025-27017 — Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record
- CVE-2025-11079 — Campcodes Farm Management System file information disclosure
- CVE-2024-47580 — Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)
- CVE-2024-47579 — Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)
- CVE-2025-12699 — ZOLL ePCR IOS Mobile Application Insertion of Sensitive Information into Externally-Accessible File or Directory
- CVE-2025-0194 — Insertion of Sensitive Information into Externally-Accessible File or Directory in GitLab
Recently published
- CVE-2026-80175 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-67361 — Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
- CVE-2026-19229 — SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
- CVE-2026-12762 — Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
- CVE-2026-15574 — Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default
- CVE-2025-36372 — IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables
- CVE-2026-50099 — Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directory
- CVE-2026-50565 — Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
- CVE-2026-46617 — Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
- CVE-2026-29114 — A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
- CVE-2019-25717 — Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure
- CVE-2026-10254 — SourceCodester Pet Grooming Management Software admin file information disclosure
- CVE-2026-49298 — Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
- CVE-2026-5434 — Improper storage of sensitive information
- CVE-2026-27173 — Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
- CVE-2023-54346 — WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download
- CVE-2026-7071 — CodeAstro Online Job Portal user-cvs file information disclosure
- CVE-2026-6160 — code-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosure
- CVE-2019-25706 — Across DR-810 ROM-0 Unauthenticated File Disclosure
- CVE-2026-33705 — Chamilo LMS has unauthenticated access to Twig template source files exposes application logic