CWE-204— Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.— MITRE CWE catalog
198 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 2 of 4
- CVE-2026-72588MEDIUMCVSS 5.3EG 5.32026-08-10
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 …
- CVE-2026-55998MEDIUMCVSS 5.3EG 5.32026-08-05
The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemte…
- CVE-2026-14202MEDIUMCVSS 5.3EG 5.32026-08-04
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
- CVE-2026-42218MEDIUMCVSS 5.3EG 5.32026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on …
- CVE-2024-23574MEDIUMCVSS 5.3EG 5.32026-07-17
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techn…
- CVE-2026-61503MEDIUMCVSS 5.3EG 5.32026-07-13
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the…
- CVE-2026-53947MEDIUMCVSS 5.3EG 5.32026-06-24
Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a r…
- CVE-2026-45294MEDIUMCVSS 5.3EG 5.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing us…
- CVE-2026-45620MEDIUMCVSS 5.3EG 5.32026-05-18
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables…
- CVE-2026-44306MEDIUMCVSS 5.3EG 5.32026-05-12
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could …
- CVE-2024-0391MEDIUMCVSS 5.3EG 5.32026-05-11
The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-fo…
- CVE-2026-20195MEDIUMCVSS 5.3EG 5.32026-05-06
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed wh…
- CVE-2026-24468MEDIUMCVSS 5.3EG 5.32026-04-20
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and prior to version 2.0.13, the /api/reset endpoint behaves differently depe…
- CVE-2026-40485MEDIUMCVSS 5.3EG 5.32026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a username exists: 404 for non-existent u…
- CVE-2025-3716MEDIUMCVSS 5.3EG 5.32026-03-30
User enumeration in ESET Protect (on-prem) via Response Timing.
- CVE-2026-33323MEDIUMCVSS 5.3EG 5.32026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return d…
- CVE-2026-33688MEDIUMCVSS 5.3EG 5.32026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allow…
- CVE-2026-30876MEDIUMCVSS 5.3EG 5.32026-03-16
Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.
- CVE-2025-69243MEDIUMCVSS 5.3EG 5.32026-03-16
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. This issue was fixed …
- CVE-2025-13460MEDIUMCVSS 5.3EG 5.32026-03-16
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.
- CVE-2026-31901MEDIUMCVSS 5.3EG 5.32026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses dependi…
- CVE-2026-31888MEDIUMCVSS 5.3EG 5.32026-03-11
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered cust…
- CVE-2026-28358MEDIUMCVSS 5.3EG 5.32026-03-02
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched i…
- CVE-2026-28288MEDIUMCVSS 5.3EG 5.32026-02-27
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the …
- CVE-2026-25138MEDIUMCVSS 5.3EG 5.32026-02-25
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Prior to versions 35.8.3, 38.5.4, and 39.3.1, the WebUI login endpoint returns distinct…
- CVE-2025-62512MEDIUMCVSS 5.3EG 5.32026-02-24
Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or emai…
- CVE-2026-27480MEDIUMCVSS 5.3EG 5.32026-02-21
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify vali…
- CVE-2026-26744MEDIUMCVSS 5.3EG 5.32026-02-19
A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an …
- CVE-2026-25509MEDIUMCVSS 5.3EG 5.32026-02-03
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, the authentication implementation in CI4MS is vulnerable to email enum…
- CVE-2026-24664MEDIUMCVSS 5.3EG 5.32026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a username enumeration vulnerability allows unauthenticated attackers to identify valid user accounts by analyzing diff…
- CVE-2026-23511MEDIUMCVSS 5.3EG 5.32026-01-15
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existenc…
- CVE-2026-21484MEDIUMCVSS 5.3EG 5.32026-01-03
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error me…
- CVE-2025-69413MEDIUMCVSS 5.3EG 5.32026-01-01
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
- CVE-2025-62181MEDIUMCVSS 5.3EG 5.32025-12-10
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a…
- CVE-2025-40806MEDIUMCVSS 5.3EG 5.32025-12-09
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determin…
- CVE-2025-65899MEDIUMCVSS 5.3EG 5.32025-12-04
Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_pa…
- CVE-2025-12994MEDIUMCVSS 5.3EG 5.32025-12-04
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December…
- CVE-2025-66307MEDIUMCVSS 5.3EG 5.32025-12-01
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Fo…
- CVE-2025-59116MEDIUMCVSS 5.3EG 5.32025-11-18
Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. Only version 4…
- CVE-2025-25236MEDIUMCVSS 5.3EG 5.32025-11-12
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying …
- CVE-2025-62236MEDIUMCVSS 5.3EG 5.32025-10-23
The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attac…
- CVE-2025-34255MEDIUMCVSS 5.3EG 5.32025-10-16
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is …
- CVE-2025-34254MEDIUMCVSS 5.3EG 5.32025-10-16
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with…
- CVE-2025-58586MEDIUMCVSS 5.3EG 5.32025-10-06
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-58442MEDIUMCVSS 5.3EG 5.32025-09-09
Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provid…
- CVE-2025-54834MEDIUMCVSS 5.3EG 5.32025-07-31
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in pla…
- CVE-2025-52899MEDIUMCVSS 5.3EG 5.32025-07-29
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot…
- CVE-2025-27451MEDIUMCVSS 5.3EG 5.32025-07-03
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-49187MEDIUMCVSS 5.3EG 5.32025-06-12
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-0163MEDIUMCVSS 5.3EG 5.32025-06-11
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →