CWE-549: Missing Password Field Masking
The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-42904 — Information Disclosure vulnerability in Application Server ABAP
- CVE-2025-13175 — Insecure Password Storage in Y Soft SafeQ 6
- CVE-2024-10122 — Topdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field masking
- CVE-2025-4526 — Dígitro NGC Explorer Configuration missing password field masking
- CVE-2026-3314 — Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
- CVE-2025-64170 — sudo-rs: Partial password reveal is possible after timeout
- CVE-2025-0148 — Zoom Jenkins Marketplace plugin - Missing Password Field Masking
Recently published
- CVE-2026-3314 — Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
- CVE-2025-13175 — Insecure Password Storage in Y Soft SafeQ 6
- CVE-2025-42904 — Information Disclosure vulnerability in Application Server ABAP
- CVE-2025-64170 — sudo-rs: Partial password reveal is possible after timeout
- CVE-2025-4526 — Dígitro NGC Explorer Configuration missing password field masking
- CVE-2025-0148 — Zoom Jenkins Marketplace plugin - Missing Password Field Masking
- CVE-2024-10122 — Topdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field masking