CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
832 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 9 of 17
- CVE-2026-91714MEDIUMCVSS 5.3EG 5.32026-09-15
Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-5802MEDIUMCVSS 5.3EG 5.32026-09-15
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message …
- CVE-2026-87566MEDIUMCVSS 5.3EG 5.32026-09-09
Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87518MEDIUMCVSS 5.3EG 5.32026-09-09
Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium secu…
- CVE-2026-11754MEDIUMCVSS 5.3EG 5.32026-08-27
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.
- CVE-2026-37064MEDIUMCVSS 5.3EG 5.32026-08-27
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen …
- CVE-2026-79181MEDIUMCVSS 5.3EG 5.32026-08-25
Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-79242MEDIUMCVSS 5.3EG 5.32026-08-25
Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79287MEDIUMCVSS 5.3EG 5.32026-08-25
Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79028MEDIUMCVSS 5.3EG 5.32026-08-25
Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79030MEDIUMCVSS 5.3EG 5.32026-08-25
Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-72699MEDIUMCVSS 5.3EG 5.32026-08-25
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already …
- CVE-2026-59502MEDIUMCVSS 5.3EG 5.32026-08-13
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall…
- CVE-2026-59640MEDIUMCVSS 5.3EG 5.32026-08-03
In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.1…
- CVE-2026-67193MEDIUMCVSS 5.3EG 5.32026-07-29
Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. …
- CVE-2026-64822MEDIUMCVSS 5.3EG 5.32026-07-21
djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attackers to identify valid accounts by observing distinct error mes…
- CVE-2026-56296MEDIUMCVSS 5.3EG 5.32026-07-11
Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid ap…
- CVE-2026-44332MEDIUMCVSS 5.3EG 5.32026-07-02
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for n…
- CVE-2026-56327MEDIUMCVSS 5.3EG 5.32026-07-01
Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers…
- CVE-2026-14112MEDIUMCVSS 5.3EG 5.32026-07-01
Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a craft…
- CVE-2026-56316MEDIUMCVSS 5.3EG 5.32026-06-21
Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response discrepancies. Atta…
- CVE-2026-45294MEDIUMCVSS 5.3EG 5.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing us…
- CVE-2026-45410MEDIUMCVSS 5.3EG 5.32026-05-28
TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed in the database, th…
- CVE-2026-26895MEDIUMCVSS 5.3EG 5.32026-04-02
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
- CVE-2026-33429MEDIUMCVSS 5.3EG 5.32026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter targeting a protected field.…
- CVE-2026-33425MEDIUMCVSS 5.3EG 5.32026-03-21
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whether a specific user is a member of a private group by observing changes in directory resu…
- CVE-2026-26185MEDIUMCVSS 5.3EG 5.32026-02-12
Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the…
- CVE-2026-25509MEDIUMCVSS 5.3EG 5.32026-02-03
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, the authentication implementation in CI4MS is vulnerable to email enum…
- CVE-2026-23849MEDIUMCVSS 5.3EG 5.32026-01-19
File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, and edit files. Prior to version 2.55.0, the JSONAuth. Auth function contains a logic flaw that allows unauthe…
- CVE-2026-21484MEDIUMCVSS 5.3EG 5.32026-01-03
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error me…
- CVE-2024-55374MEDIUMCVSS 5.3EG 5.32026-01-02
REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
- CVE-2023-53943MEDIUMCVSS 5.3EG 5.32025-12-18
GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password re…
- CVE-2020-36888MEDIUMCVSS 5.3EG 5.32025-12-10
SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguis…
- CVE-2025-39665MEDIUMCVSS 5.3EG 5.32025-12-03
User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.
- CVE-2025-56423MEDIUMCVSS 5.3EG 5.32025-11-24
An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages
- CVE-2025-59716MEDIUMCVSS 5.3EG 5.32025-11-05
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently whe…
- CVE-2025-54477MEDIUMCVSS 5.3EG 5.32025-09-30
Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
- CVE-2025-43786MEDIUMCVSS 5.3EG 5.32025-09-09
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers…
- CVE-2025-57770MEDIUMCVSS 5.3EG 5.32025-08-22
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Versions 4.0.0 to 4.0.2, 3.0.0 to 3.3.6, and all versions prior to 2.71.15 are vulnerable to a username enumeration issue…
- CVE-2025-43751MEDIUMCVSS 5.3EG 5.32025-08-22
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, …
- CVE-2025-24391MEDIUMCVSS 5.3EG 5.32025-07-14
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addre…
- CVE-2023-38327MEDIUMCVSS 5.3EG 5.32025-07-11
An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web applications based on server response.
- CVE-2025-27451MEDIUMCVSS 5.3EG 5.32025-07-03
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-52576MEDIUMCVSS 5.3EG 5.32025-06-25
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumeration and IP spoofing-based brute-force protection bypass. By analyzing login behavior and ab…
- CVE-2024-47057MEDIUMCVSS 5.3EG 5.32025-05-28
SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames. User Enumeration via Timin…
- CVE-2025-3939MEDIUMCVSS 5.3EG 5.32025-05-22
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before…
- CVE-2021-47664MEDIUMCVSS 5.3EG 5.32025-04-24
Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames.
- CVE-2025-31124MEDIUMCVSS 5.3EG 5.32025-03-31
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the …
- CVE-2025-30344MEDIUMCVSS 5.3EG 5.32025-03-21
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashin…
- CVE-2023-37482MEDIUMCVSS 5.3EG 5.32025-02-11
The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid …
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →