CWE-204— Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.— MITRE CWE catalog
181 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 3 of 4
- CVE-2025-42903MEDIUMCVSS 4.3EG 4.32025-10-14
A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality w…
- CVE-2025-46390HIGHCVSS 7.5EG 7.52025-08-06
CWE-204: Observable Response Discrepancy
- CVE-2025-46736MEDIUMCVSS 5.3EG 5.32025-05-06
Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. The issue is patc…
- CVE-2025-48015LOWCVSS 3.7EG 3.72025-05-20
Failed login response could be different depending on whether the username was local or central.
- CVE-2025-49187MEDIUMCVSS 5.3EG 5.32025-06-12
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-52899MEDIUMCVSS 5.3EG 5.32025-07-29
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot…
- CVE-2025-54129MEDIUMCVSS 4.3EG 4.32025-07-21
HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response when requesting the data of a valid user and a 404 response…
- CVE-2025-54834MEDIUMCVSS 5.3EG 5.32025-07-31
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in pla…
- CVE-2025-5485HIGHCVSS 8.6EG 8.62025-06-12
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from …
- CVE-2025-56764MEDIUMCVSS 5.3EG 6.52025-09-29
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
- CVE-2025-58442MEDIUMCVSS 5.3EG 5.32025-09-09
Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provid…
- CVE-2025-58586MEDIUMCVSS 5.3EG 5.32025-10-06
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-59116MEDIUMCVSS 5.3EG 5.32025-11-18
Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. Only version 4…
- CVE-2025-61789MEDIUMCVSS 6.5EG 6.52025-10-16
Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hi…
- CVE-2025-61907MEDIUMCVSS 6.5EG 6.52025-10-16
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. Th…
- CVE-2025-62181MEDIUMCVSS 5.3EG 5.32025-12-10
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a…
- CVE-2025-62236MEDIUMCVSS 5.3EG 5.32025-10-23
The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attac…
- CVE-2025-62512MEDIUMCVSS 5.3EG 5.32026-02-24
Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or emai…
- CVE-2025-65899MEDIUMCVSS 5.3EG 5.32025-12-04
Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_pa…
- CVE-2025-66307MEDIUMCVSS 5.3EG 5.32025-12-01
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Fo…
- CVE-2025-67500LOWCVSS 3.7EG 3.72025-12-10
Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow che…
- CVE-2025-67806LOWCVSS 3.7EG 3.72026-04-01
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer …
- CVE-2025-67807MEDIUMCVSS 4.7EG 4.72026-04-01
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer…
- CVE-2025-67874MEDIUMCVSS 6.5EG 6.52025-12-16
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of …
- CVE-2025-69243MEDIUMCVSS 5.3EG 5.32026-03-16
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. This issue was fixed …
- CVE-2025-69413MEDIUMCVSS 5.3EG 5.32026-01-01
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
- CVE-2025-9109LOWCVSS 3.7EG 3.72025-08-18
A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observa…
- CVE-2025-9824MEDIUMCVSS 5.9EG 5.92025-09-03
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has…
- CVE-2026-14202MEDIUMCVSS 5.3EG 5.32026-08-04
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
- CVE-2026-14672MEDIUMCVSS 5.3EG 5.32026-08-13
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iteration…
- CVE-2026-15747CRITICALCVSS 9.1EG 9.12026-07-14
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, …
- CVE-2026-19965LOWCVSS 3.7EG 3.72026-08-17
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. Th…
- CVE-2026-20195MEDIUMCVSS 5.3EG 5.32026-05-06
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed wh…
- CVE-2026-21484MEDIUMCVSS 5.3EG 5.32026-01-03
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error me…
- CVE-2026-23511MEDIUMCVSS 5.3EG 5.32026-01-15
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existenc…
- CVE-2026-24097MEDIUMCVSS 4.3EG 4.32026-03-13
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_…
- CVE-2026-24332MEDIUMCVSS 4.3EG 4.32026-01-22
Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "o…
- CVE-2026-24468MEDIUMCVSS 5.3EG 5.32026-04-20
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and prior to version 2.0.13, the /api/reset endpoint behaves differently depe…
- CVE-2026-24664MEDIUMCVSS 5.3EG 5.32026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a username enumeration vulnerability allows unauthenticated attackers to identify valid user accounts by analyzing diff…
- CVE-2026-25138MEDIUMCVSS 5.3EG 5.32026-02-25
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Prior to versions 35.8.3, 38.5.4, and 39.3.1, the WebUI login endpoint returns distinct…
- CVE-2026-25509MEDIUMCVSS 5.3EG 5.32026-02-03
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, the authentication implementation in CI4MS is vulnerable to email enum…
- CVE-2026-26744MEDIUMCVSS 5.3EG 5.32026-02-19
A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an …
- CVE-2026-27462HIGHCVSS 7.5EG 7.52026-08-21
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has…
- CVE-2026-27480MEDIUMCVSS 5.3EG 5.32026-02-21
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify vali…
- CVE-2026-28288MEDIUMCVSS 5.3EG 5.32026-02-27
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the …
- CVE-2026-28358MEDIUMCVSS 5.3EG 5.32026-03-02
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched i…
- CVE-2026-2859MEDIUMCVSS 4.3EG 4.32026-03-13
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint,…
- CVE-2026-30876MEDIUMCVSS 5.3EG 5.32026-03-16
Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.
- CVE-2026-31888MEDIUMCVSS 5.3EG 5.32026-03-11
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered cust…
- CVE-2026-31901MEDIUMCVSS 5.3EG 5.32026-03-11
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses dependi…
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →