CWE-359— Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.— MITRE CWE catalog
218 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-359page 4 of 5
- CVE-2023-7014MEDIUMCVSS 5.3EG 5.32024-02-05
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible fo…
- CVE-2023-25819MEDIUMCVSS 5.3EG 5.32023-03-04
Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `…
- CVE-2022-41936MEDIUMCVSS 5.3EG 5.32022-11-22
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unaut…
- CVE-2022-2720MEDIUMCVSS 5.3EG 5.32022-10-12
In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.
- CVE-2022-24820MEDIUMCVSS 5.3EG 5.32022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem ha…
- CVE-2022-24819MEDIUMCVSS 5.3EG 5.32022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been p…
- CVE-2021-28559MEDIUMCVSS 5.3EG 5.32021-09-02
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerab…
- CVE-2021-22876MEDIUMCVSS 5.3EG 5.32021-04-01
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when au…
- CVE-2019-15623MEDIUMCVSS 5.3EG 5.32020-02-04
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
- CVE-2017-16769MEDIUMCVSS 5.3EG 5.32018-02-23
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
- CVE-2026-39372MEDIUMCVSS 4.9EG 4.92026-09-25
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an…
- CVE-2025-66510MEDIUMCVSS 4.9EG 4.92025-12-05
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal d…
- CVE-2024-13953MEDIUMCVSS 4.9EG 4.92025-05-22
Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- CVE-2021-46687MEDIUMCVSS 4.9EG 4.92022-07-06
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prio…
- CVE-2022-41971MEDIUMCVSS 4.8EG 4.82022-12-01
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacke…
- CVE-2026-54565MEDIUMCVSS 4.7EG 4.72026-09-17
rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages, b…
- CVE-2026-28963MEDIUMCVSS 4.6EG 4.62026-05-11
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.
- CVE-2026-20834MEDIUMCVSS 4.6EG 4.62026-01-13
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
- CVE-2025-36131MEDIUMCVSS 4.6EG 4.62025-11-07
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party w…
- CVE-2025-43259MEDIUMCVSS 4.6EG 4.62025-07-30
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensit…
- CVE-2025-43310MEDIUMCVSS 4.4EG 4.42025-09-15
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to trick a user into copying sensitive data to the pasteboard.
- CVE-2025-53765MEDIUMCVSS 4.4EG 4.42025-08-12
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
- CVE-2026-102579MEDIUMCVSS 4.3EG 4.32026-09-30
A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. Th…
- CVE-2026-88875MEDIUMCVSS 4.3EG 4.32026-09-10
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and API…
- CVE-2026-55496MEDIUMCVSS 4.3EG 4.32026-07-24
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to en…
- CVE-2026-58510MEDIUMCVSS 4.3EG 4.32026-07-21
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2025-53374MEDIUMCVSS 4.3EG 4.32025-07-07
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in t…
- CVE-2025-0679MEDIUMCVSS 4.3EG 4.32025-05-22
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially…
- CVE-2025-25042MEDIUMCVSS 4.3EG 4.32025-03-18
A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on th…
- CVE-2024-13228MEDIUMCVSS 4.3EG 4.32025-03-11
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, wi…
- CVE-2024-13217MEDIUMCVSS 4.3EG 4.32025-02-27
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attacker…
- CVE-2024-13216MEDIUMCVSS 4.3EG 4.32025-01-31
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.p…
- CVE-2024-13215MEDIUMCVSS 4.3EG 4.32025-01-15
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possibl…
- CVE-2024-37070MEDIUMCVSS 4.3EG 4.32024-11-19
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
- CVE-2024-44113MEDIUMCVSS 4.3EG 4.32024-09-10
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate informa…
- CVE-2024-41729MEDIUMCVSS 4.3EG 4.32024-09-10
Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limite…
- CVE-2024-6053MEDIUMCVSS 4.3EG 4.32024-08-28
Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a …
- CVE-2024-4767MEDIUMCVSS 4.3EG 4.32024-05-14
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ES…
- CVE-2023-6630MEDIUMCVSS 4.3EG 4.32024-01-11
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missin…
- CVE-2025-52602MEDIUMCVSS 4.2EG 4.22025-11-05
HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs). An attacker can…
- CVE-2024-41780MEDIUMCVSS 4.2EG 4.22025-01-03
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.
- CVE-2024-29888MEDIUMCVSS 4.2EG 4.22024-03-27
Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which …
- CVE-2023-44255MEDIUMCVSS 4.1EG 4.12024-11-12
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permi…
- CVE-2025-10859MEDIUMCVSS 4.0EG 4.02025-09-30
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs. This vulnerability was fixed in…
- CVE-2025-43217MEDIUMCVSS 4.0EG 4.02025-07-30
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for microphone or camera access may not be correctly displayed.
- CVE-2025-1939LOWCVSS 3.9EG 3.92025-03-04
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This v…
- CVE-2025-51586LOWCVSS 3.7EG 3.72025-09-08
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
- CVE-2023-29203LOWCVSS 3.7EG 3.72023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgs…
- CVE-2025-3950LOWCVSS 3.5EG 3.52026-01-09
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images th…
- CVE-2024-42325LOWCVSS 3.5EG 3.52025-04-02
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
Map vulnerabilities like CWE-359 to your infrastructure
EchelonGraph correlates every CVE — across CWE-359 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →