CWE-538— Insertion of Sensitive Information into Externally-Accessible File or Directory
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.— MITRE CWE catalog
102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-538page 2 of 3
- CVE-2025-31421MEDIUMCVSS 5.8EG 5.82025-04-04
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Oblak Studio Srbtranslatin srbtranslatin allows Retrieve Embedded Sensitive Data.This issue affects Srbtranslatin: from n/a through <= 3.2.0.
- CVE-2025-31558MEDIUMCVSS 5.8EG 5.82025-04-03
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Greg TailPress tailpress allows Retrieve Embedded Sensitive Data.This issue affects TailPress: from n/a through <= 0.4.4.
- CVE-2025-31550MEDIUMCVSS 5.8EG 5.82025-04-01
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in thom4 WP-LESS wp-less allows Retrieve Embedded Sensitive Data.This issue affects WP-LESS: from n/a through <= 1.9.6.
- CVE-2025-22633MEDIUMCVSS 5.8EG 5.82025-02-23
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in StellarWP Give – Divi Donation Modules give-donation-modules-for-divi allows Retrieve Embedded Sensitive Data.This issue affects Give – Di…
- CVE-2026-69507MEDIUMCVSS 5.7EG 5.72026-09-08
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.
- CVE-2025-12699MEDIUMCVSS 5.5EG 5.52026-02-10
The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PCR fields (run number, incident, call sign, notes) are interpreted as HTML/JS when the app prints or renders that conten…
- CVE-2025-36058MEDIUMCVSS 5.5EG 5.52026-01-20
IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow…
- CVE-2025-46602MEDIUMCVSS 5.5EG 5.52025-10-27
Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit thi…
- CVE-2025-20665MEDIUMCVSS 5.5EG 5.52025-05-05
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for…
- CVE-2023-38558MEDIUMCVSS 5.5EG 5.52023-09-14
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attack…
- CVE-2023-4480MEDIUMCVSS 5.5EG 5.52023-09-05
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker can send a crafted request that allows them to read the contents of files on the system accessible within the priv…
- CVE-2026-19229MEDIUMCVSS 5.3EG 5.32026-08-07
A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and di…
- CVE-2026-12762MEDIUMCVSS 5.3EG 5.32026-08-05
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
- CVE-2026-10254MEDIUMCVSS 5.3EG 5.32026-06-01
A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The …
- CVE-2026-7071MEDIUMCVSS 5.3EG 5.32026-04-27
A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file and directory information exposure. Remo…
- CVE-2026-6160MEDIUMCVSS 5.3EG 5.32026-04-13
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information …
- CVE-2026-33705MEDIUMCVSS 5.3EG 5.32026-04-10
Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic…
- CVE-2025-11891MEDIUMCVSS 5.3EG 5.32025-11-11
The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially…
- CVE-2025-27150MEDIUMCVSS 5.3EG 5.32025-03-04
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely…
- CVE-2025-22773MEDIUMCVSS 5.3EG 5.32025-01-15
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
- CVE-2025-22306MEDIUMCVSS 5.3EG 5.32025-01-07
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Spencer Haws Link Whisper Free link-whisper.This issue affects Link Whisper Free: from n/a through <= 0.7.7.
- CVE-2024-9671MEDIUMCVSS 5.3EG 5.32024-10-09
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed.
- CVE-2024-21501MEDIUMCVSS 5.3EG 5.32024-02-24
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An atta…
- CVE-2024-0191MEDIUMCVSS 5.3EG 5.32024-01-02
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/uploads/. The manipulation leads to file and directory information exposure.…
- CVE-2023-4933MEDIUMCVSS 5.3EG 5.32023-10-16
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the aut…
- CVE-2017-9947MEDIUMCVSS 5.3EG 5.32017-10-23
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server …
- CVE-2022-26329MEDIUMCVSS 1.8EG 5.32023-01-26
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Man…
- CVE-2022-0013MEDIUMCVSS 5.0EG 5.02022-01-12
A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This i…
- CVE-2014-0772MEDIUMCVSS v2 5.0EG 5.02014-04-12
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the curren…
- CVE-2014-0771MEDIUMCVSS v2 5.0EG 5.02014-04-12
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to the caller in JavaScript. The URLs are accessed in the security context of the current…
- CVE-2026-50565MEDIUMCVSS 4.9EG 4.92026-06-10
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-build…
- CVE-2021-1406MEDIUMCVSS 4.9EG 4.92021-04-08
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an a…
- CVE-2026-50099MEDIUMCVSS 4.6EG 4.62026-06-12
During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, an…
- CVE-2022-20864MEDIUMCVSS 4.6EG 4.62022-10-10
A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. Th…
- CVE-2018-4847MEDIUMCVSS 4.6EG 4.62018-04-23
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an at…
- CVE-2026-2817MEDIUMCVSS 4.4EG 4.42026-02-19
Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extra…
- CVE-2022-43933MEDIUMCVSS 4.4EG 4.42024-11-21
An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. …
- CVE-2019-25717MEDIUMCVSS 4.3EG 4.32026-06-02
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device interna…
- CVE-2025-58458MEDIUMCVSS 4.3EG 4.32025-09-03
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit…
- CVE-2025-57734MEDIUMCVSS 4.3EG 4.32025-08-20
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
- CVE-2025-8452MEDIUMCVSS 4.3EG 4.32025-08-12
By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the …
- CVE-2019-12623MEDIUMCVSS 4.3EG 4.32019-08-21
A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulne…
- CVE-2019-10320MEDIUMCVSS 4.3EG 4.32019-05-21
Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of file…
- CVE-2018-16970MEDIUMCVSS 4.3EG 4.32018-09-12
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
- CVE-2025-25586MEDIUMCVSS 4.2EG 4.22025-03-18
yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.
- CVE-2021-32822MEDIUMCVSS 4.0EG 4.02021-08-16
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data w…
- CVE-2023-5937LOWCVSS 3.8EG 3.82024-05-15
On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.
- CVE-2026-80175LOWCVSS 3.3EG 3.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged atta…
- CVE-2017-5387LOWCVSS 3.3EG 3.32018-06-11
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded locally. This vuln…
- CVE-2018-20932LOWCVSS 2.7EG 2.72019-08-01
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
Map vulnerabilities like CWE-538 to your infrastructure
EchelonGraph correlates every CVE — across CWE-538 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →