CWE-359— Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.— MITRE CWE catalog
218 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-359page 2 of 5
- CVE-2024-36677HIGHCVSS 7.5EG 7.52024-06-19
In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account of the Shop if the module is not installed OR if a secret accessible to admini…
- CVE-2024-33271HIGHCVSS 7.5EG 7.52024-04-29
An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.
- CVE-2024-28387HIGHCVSS 7.5EG 7.52024-03-25
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.
- CVE-2023-5983HIGHCVSS 7.5EG 7.52023-11-22
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation allows Retrieve Embedded Sensitive Data. This issue affects Pharmacy Automation: before 2.1.133.0.
- CVE-2023-44156HIGHCVSS 7.5EG 7.52023-09-27
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2023-35151HIGHCVSS 7.5EG 7.52023-06-23
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activat…
- CVE-2022-36091HIGHCVSS 7.5EG 7.52022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 an…
- CVE-2021-3980HIGHCVSS 7.5EG 7.52021-12-03
elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
- CVE-2021-21823HIGHCVSS 7.5EG 7.52021-08-20
An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can lead to the disclosure of sensitive information.
- CVE-2025-34441HIGHCVSS 6.9EG 7.52025-12-17
AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violati…
- CVE-2021-36723HIGHCVSS 6.1EG 7.52021-12-29
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
- CVE-2025-43469HIGHCVSS 5.5EG 7.52025-11-04
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-43439HIGHCVSS 5.5EG 7.52025-11-04
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visionOS 26.1. An app may be able to fingerprint the user.
- CVE-2025-43409HIGHCVSS 5.5EG 7.52025-11-04
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
- CVE-2025-43389HIGHCVSS 5.5EG 7.52025-11-04
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to…
- CVE-2025-43452HIGHCVSS 4.6EG 7.52025-11-04
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.
- CVE-2026-58296HIGHCVSS 7.1EG 7.12026-07-03
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58297HIGHCVSS 7.1EG 7.12026-07-03
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- CVE-2026-49344HIGHCVSS 7.1EG 7.12026-06-19
Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts a JSON DSL (`from` / `select` / `filters` / `traverse` / `ou…
- CVE-2025-13477HIGHCVSS 7.1EG 7.12026-05-21
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 2105…
- CVE-2025-14317HIGHCVSS 7.1EG 7.12026-01-14
In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue…
- CVE-2025-24355HIGHCVSS 7.1EG 7.12025-01-24
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pip…
- CVE-2024-30056HIGHCVSS 7.1EG 7.12024-05-25
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2025-62362MEDIUMCVSS 6.9EG 6.92025-10-13
gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing t…
- CVE-2024-37136MEDIUMCVSS 6.8EG 6.82024-09-03
Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to informati…
- CVE-2026-61588MEDIUMCVSS 6.5EG 6.52026-09-16
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client…
- CVE-2026-76855MEDIUMCVSS 6.5EG 6.52026-09-15
Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit co…
- CVE-2026-24078MEDIUMCVSS 6.5EG 6.52026-08-04
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
- CVE-2026-57960MEDIUMCVSS 6.5EG 6.52026-06-29
Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id…
- CVE-2025-66171MEDIUMCVSS 6.5EG 6.52026-05-08
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs …
- CVE-2026-7382MEDIUMCVSS 6.5EG 6.52026-04-30
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.2020…
- CVE-2025-0969MEDIUMCVSS 6.5EG 6.52025-12-13
The Brizy – Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.16 via the get_users() function. This makes it possible for authenticated attackers, with Contributor…
- CVE-2025-66027MEDIUMCVSS 6.5EG 6.52025-11-29
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants…
- CVE-2025-41685MEDIUMCVSS 6.5EG 6.52025-08-19
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.
- CVE-2025-54125MEDIUMCVSS 6.5EG 6.52025-08-06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 th…
- CVE-2025-54124MEDIUMCVSS 6.5EG 6.52025-08-06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-r…
- CVE-2025-26816MEDIUMCVSS 6.5EG 6.52025-03-19
A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.
- CVE-2024-42494MEDIUMCVSS 6.5EG 6.52024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services
- CVE-2024-47087MEDIUMCVSS 6.5EG 6.52024-09-19
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating paramet…
- CVE-2024-47085MEDIUMCVSS 6.5EG 6.52024-09-19
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by ma…
- CVE-2024-45787MEDIUMCVSS 6.5EG 6.52024-09-11
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter t…
- CVE-2024-27850MEDIUMCVSS 6.5EG 6.52024-06-10
This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.
- CVE-2024-29987MEDIUMCVSS 6.5EG 6.52024-04-18
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2023-6695MEDIUMCVSS 6.5EG 6.52024-04-09
The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and ab…
- CVE-2023-22918MEDIUMCVSS 6.5EG 6.52023-04-24
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, U…
- CVE-2023-2239MEDIUMCVSS 6.5EG 6.52023-04-22
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.
- CVE-2022-20942MEDIUMCVSS 6.5EG 6.52022-11-04
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authent…
- CVE-2022-1365MEDIUMCVSS 6.5EG 6.52022-04-15
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
- CVE-2022-0155MEDIUMCVSS 6.5EG 6.52022-01-10
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
- CVE-2020-1688MEDIUMCVSS 6.5EG 6.52020-10-16
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator …
Map vulnerabilities like CWE-359 to your infrastructure
EchelonGraph correlates every CVE — across CWE-359 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →