CWE-540: Inclusion of Sensitive Information in Source Code
Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
30 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-23215 — PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
- CVE-2024-38647 — QNAP AI Core
- CVE-2025-49182 — Credential disclosure
- CVE-2024-38327 — IBM Analytics Content Hub information disclosure
- CVE-2024-1272 — Information Disclosure to Source Code in TNB Mobile Solutions' Cockpit Software
- CVE-2026-45728 — Algernon: Single-file mode unconditionally enables debug mode
- CVE-2026-4155 — ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability
- CVE-2026-35383 — Bentley Systems iTwin Platform exposed access token
- CVE-2026-16581 — Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
- CVE-2025-0923 — IBM Cognos Analytics information disclosure
- CVE-2025-3403 — Vivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in source
- CVE-2026-22275 — Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sen
- CVE-2025-36299 — IBM Planning Analytics Information Disclosure
- CVE-2024-39729 — IBM Datacap Navigator information disclosure
- CVE-2024-27257 — IBM OpenPages information disclosure
- CVE-2024-9596 — Inclusion of Sensitive Information in Source Code in GitLab
Recently published
- CVE-2026-16581 — Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
- CVE-2026-45728 — Algernon: Single-file mode unconditionally enables debug mode
- CVE-2026-4155 — ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability
- CVE-2026-35383 — Bentley Systems iTwin Platform exposed access token
- CVE-2026-22275 — Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sen
- CVE-2025-36299 — IBM Planning Analytics Information Disclosure
- CVE-2024-38327 — IBM Analytics Content Hub information disclosure
- CVE-2025-49182 — Credential disclosure
- CVE-2025-0923 — IBM Cognos Analytics information disclosure
- CVE-2025-3403 — Vivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in source
- CVE-2025-23215 — PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
- CVE-2024-38647 — QNAP AI Core
- CVE-2024-9596 — Inclusion of Sensitive Information in Source Code in GitLab
- CVE-2024-27257 — IBM OpenPages information disclosure
- CVE-2024-39729 — IBM Datacap Navigator information disclosure
- CVE-2024-1272 — Information Disclosure to Source Code in TNB Mobile Solutions' Cockpit Software