CWE-598— Use of HTTP Request With Sensitive Query String
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.— MITRE CWE catalog
99 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-598page 2 of 2
- CVE-2017-8443MEDIUMCVSS 6.5EG 6.52017-06-30
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials w…
- CVE-2025-1738MEDIUMCVSS 6.2EG 6.22025-02-27
A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity, exposing this sensitive information to a third party.
- CVE-2026-2237MEDIUMCVSS 5.5EG 6.22026-05-27
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.
- CVE-2026-88897MEDIUMCVSS 5.9EG 5.92026-09-10
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant f…
- CVE-2026-61614MEDIUMCVSS 5.9EG 5.92026-09-04
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentia…
- CVE-2025-14811MEDIUMCVSS 5.9EG 5.92026-03-13
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained us…
- CVE-2025-59873MEDIUMCVSS 5.9EG 5.92026-02-23
An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits sensitive session tokens and authentication identifiers within the URL query parameters . An attacker who gains access t…
- CVE-2024-41738MEDIUMCVSS 5.9EG 5.92024-11-01
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
- CVE-2025-8997MEDIUMCVSS 5.7EG 5.72025-08-25
An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.
- CVE-2024-12012MEDIUMCVSS 5.7EG 5.72025-02-13
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as par…
- CVE-2024-32931MEDIUMCVSS 5.7EG 5.72024-08-01
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
- CVE-2026-82181MEDIUMCVSS 5.5EG 5.52026-08-28
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
- CVE-2026-47768MEDIUMCVSS 5.5EG 5.52026-06-10
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version …
- CVE-2025-54542MEDIUMCVSS 5.5EG 5.52025-08-28
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability…
- CVE-2025-51651MEDIUMCVSS 5.5EG 5.52025-07-14
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.
- CVE-2023-6287MEDIUMCVSS 5.5EG 5.52023-11-27
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.
- CVE-2023-22307MEDIUMCVSS 5.5EG 5.52023-04-18
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
- CVE-2025-31954MEDIUMCVSS 5.4EG 5.42025-11-05
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially a…
- CVE-2026-55375MEDIUMCVSS 5.3EG 5.32026-06-19
canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing ac…
- CVE-2026-37504MEDIUMCVSS 5.3EG 5.32026-05-01
Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /a…
- CVE-2026-31381MEDIUMCVSS 5.3EG 5.32026-03-20
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
- CVE-2026-26196MEDIUMCVSS 5.3EG 5.32026-03-05
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in v…
- CVE-2025-58584MEDIUMCVSS 5.3EG 5.32025-10-06
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk tha…
- CVE-2025-40742MEDIUMCVSS 5.3EG 5.32025-07-08
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP…
- CVE-2025-49188MEDIUMCVSS 5.3EG 5.32025-06-12
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
- CVE-2025-52901MEDIUMCVSS 4.5EG 4.52025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) …
- CVE-2026-27949MEDIUMCVSS 4.3EG 4.32026-04-07
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an…
- CVE-2026-33620MEDIUMCVSS 4.3EG 4.32026-03-26
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` through `v0.8.3` accepted the API token from a `token` URL query parameter in addition to the `Authorization` header. When a …
- CVE-2025-32916MEDIUMCVSS 4.3EG 4.32025-10-09
Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various…
- CVE-2025-50709MEDIUMCVSS 4.3EG 4.32025-09-17
An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
- CVE-2024-9877MEDIUMCVSS 4.3EG 4.32025-04-30
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.
- CVE-2023-50954MEDIUMCVSS 4.3EG 4.32024-06-30
IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.
- CVE-2025-26058MEDIUMCVSS 4.2EG 4.22025-02-18
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
- CVE-2025-3943MEDIUMCVSS 4.1EG 4.12025-05-22
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Fra…
- CVE-2023-25524MEDIUMCVSS 4.0EG 4.02023-08-03
NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate…
- CVE-2026-16207LOWCVSS 3.7EG 3.72026-07-19
A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The att…
- CVE-2025-2356LOWCVSS 3.7EG 3.72025-03-17
A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API Handler. The manipulation leads to use of get request method with sensitive query…
- CVE-2025-0730LOWCVSS 3.7EG 3.72025-01-27
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. The manipulation of …
- CVE-2023-32335LOWCVSS 3.7EG 3.72024-03-13
IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referr…
- CVE-2023-50328LOWCVSS 3.7EG 3.72024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.
- CVE-2024-2745LOWCVSS 3.3EG 3.32024-04-02
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.�…
- CVE-2025-14808LOWCVSS 3.1EG 3.12026-03-25
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
- CVE-2025-3637LOWCVSS 3.1EG 3.12025-04-25
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages …
- CVE-2026-10078LOWCVSS 2.7EG 2.72026-05-29
A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext in URL query parameters during POST requests to th…
- CVE-2022-34452LOWCVSS 2.7EG 2.72023-02-10
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs.
- CVE-2025-62317LOWCVSS 2.6EG 2.62026-05-14
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended i…
- CVE-2024-28238LOWCVSS 2.3EG 2.32024-03-12
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various …
- CVE-2025-32021LOWCVSS 2.2EG 2.22025-04-15
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters duri…
- CVE-2023-45716LOWCVSS 1.7EG 1.72024-02-09
Sametime is impacted by sensitive information passed in URL.
Map vulnerabilities like CWE-598 to your infrastructure
EchelonGraph correlates every CVE — across CWE-598 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →