CWE-204— Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.— MITRE CWE catalog
198 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 4 of 4
- CVE-2022-41697MEDIUMCVSS 5.3EG 5.32022-12-22
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigg…
- CVE-2022-1989MEDIUMCVSS 5.3EG 5.32022-08-23
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
- CVE-2022-31248MEDIUMCVSS 5.3EG 5.32022-06-22
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions …
- CVE-2022-0564MEDIUMCVSS 5.3EG 5.32022-02-21
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful explo…
- CVE-2021-39189MEDIUMCVSS 5.3EG 5.32021-09-15
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may appl…
- CVE-2016-9499MEDIUMCVSS 5.3EG 5.32018-07-13
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
- CVE-2021-36201MEDIUMCVSS 4.3EG 5.32022-10-11
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
- CVE-2026-59785MEDIUMCVSS 5.1EG 5.12026-10-05
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them u…
- CVE-2026-71458MEDIUMCVSS 5.0EG 5.02026-09-23
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 de…
- CVE-2026-34319MEDIUMCVSS 5.0EG 5.02026-04-21
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker…
- CVE-2025-67807MEDIUMCVSS 4.7EG 4.72026-04-01
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer…
- CVE-2026-78584MEDIUMCVSS 4.3EG 4.32026-09-02
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a s…
- CVE-2026-47083MEDIUMCVSS 4.3EG 4.32026-07-16
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Se…
- CVE-2026-53422MEDIUMCVSS 4.3EG 4.32026-07-02
Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler i…
- CVE-2026-53908MEDIUMCVSS 4.3EG 4.32026-07-01
MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset operations. An attacker can lev…
- CVE-2026-39851MEDIUMCVSS 4.3EG 4.32026-04-08
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed…
- CVE-2026-2859MEDIUMCVSS 4.3EG 4.32026-03-13
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint,…
- CVE-2026-24097MEDIUMCVSS 4.3EG 4.32026-03-13
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_…
- CVE-2026-24332MEDIUMCVSS 4.3EG 4.32026-01-22
Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "o…
- CVE-2025-42903MEDIUMCVSS 4.3EG 4.32025-10-14
A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low impact on confidentiality w…
- CVE-2025-54129MEDIUMCVSS 4.3EG 4.32025-07-21
HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response when requesting the data of a valid user and a 404 response…
- CVE-2023-47159MEDIUMCVSS 4.3EG 4.32025-01-27
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
- CVE-2024-47129MEDIUMCVSS 4.3EG 4.32024-09-26
The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.
- CVE-2024-41715MEDIUMCVSS 4.3EG 4.32024-09-26
The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.
- CVE-2023-23584MEDIUMCVSS 4.3EG 4.32023-12-18
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 p…
- CVE-2023-39343MEDIUMCVSS 4.3EG 4.32023-08-04
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony …
- CVE-2026-71462MEDIUMCVSS 4.1EG 4.12026-09-23
StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant …
- CVE-2023-50306MEDIUMCVSS 4.0EG 4.02024-02-20
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.
- CVE-2026-84307LOWCVSS 3.7EG 3.72026-09-01
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating canAcce…
- CVE-2026-19965LOWCVSS 3.7EG 3.72026-08-17
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. Th…
- CVE-2026-44753LOWCVSS 3.7EG 3.72026-07-14
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation …
- CVE-2026-8242LOWCVSS 3.7EG 3.72026-05-10
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The…
- CVE-2025-67806LOWCVSS 3.7EG 3.72026-04-01
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer …
- CVE-2026-4045LOWCVSS 3.7EG 3.72026-03-12
A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be ex…
- CVE-2025-67500LOWCVSS 3.7EG 3.72025-12-10
Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 through 4.3.14, 4.4.0-beta.1 through 4.4.9, 4.5.0-beta.1 through 4.5.2 have discrepancies in error handling which allow che…
- CVE-2025-9109LOWCVSS 3.7EG 3.72025-08-18
A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observa…
- CVE-2025-48015LOWCVSS 3.7EG 3.72025-05-20
Failed login response could be different depending on whether the username was local or central.
- CVE-2025-24023LOWCVSS 3.7EG 3.72025-03-03
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This …
- CVE-2024-42174LOWCVSS 3.7EG 3.72025-01-11
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid usernames.
- CVE-2024-13198LOWCVSS 3.7EG 3.72025-01-09
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack…
- CVE-2024-13028LOWCVSS 3.7EG 3.72024-12-29
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response…
- CVE-2024-12663LOWCVSS 3.7EG 3.72024-12-16
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable respo…
- CVE-2024-6056LOWCVSS 3.7EG 3.72024-06-17
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulat…
- CVE-2024-28868LOWCVSS 3.7EG 3.72024-03-20
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disabl…
- CVE-2024-2482LOWCVSS 3.7EG 3.72024-03-15
A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /check_availability.php of the component HTTP POST Reques…
- CVE-2020-11063LOWCVSS 3.7EG 3.72020-05-13
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigne…
- CVE-2024-31870LOWCVSS 3.3EG 3.32024-06-15
IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor …
- CVE-2026-102587LOWCVSS 2.7EG 2.72026-09-30
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view …
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →