CWE-256— Plaintext Storage of a Password
The product stores a password in plaintext within resources such as memory or files.— MITRE CWE catalog
254 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-256page 6 of 6
- CVE-2026-57302MEDIUMCVSS 4.3EG 4.32026-06-24
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.
- CVE-2026-61886MEDIUMCVSS 6.5EG 6.52026-07-24
Weintek cMT3092X HMI stores user account passwords in plaintext.
- CVE-2026-6500MEDIUMCVSS 4.8EG 4.82026-05-04
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.
- CVE-2026-6597LOWCVSS 2.7EG 2.72026-04-20
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes un…
Map vulnerabilities like CWE-256 to your infrastructure
EchelonGraph correlates every CVE — across CWE-256 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →